Loi n° 2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité (Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercriminality)
cm-cyber-2010 · Act
Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercriminality is Cameroon's foundational legislation governing the security of electronic communications networks and the prevention and prosecution of cybercrime. It applies to all natural and legal persons who produce, transmit, store, process, or receive data via electronic communications networks in Cameroon, irrespective of nationality or location. The law is organised around three principal objectives: building trust in digital technology infrastructure, securing electronic communications networks and information systems, and protecting individuals' fundamental rights, in particular the right to human dignity, honour, and respect of privacy. On data protection, the law does not establish a standalone data protection regime. Its provisions are incidental to its primary cybersecurity mandate. Electronic communications operators and service providers are required to protect the personal data, traffic information, and privacy of users. Operators must retain connection and traffic data for a mandatory period of ten years and disclose it to competent authorities upon request. The law also criminalises identity theft and the unauthorised interception of private electronic communications. Cybercrime offences are defined in sections 60 to 89 and include: unauthorised access to computer systems, manipulation of electronic data, online fraud and financial crimes, dissemination of child sexual abuse material, hate speech communicated by electronic means, misuse of electronic certification, and violation of individuals' digital privacy. Penalties range from fines to custodial sentences of up to 20 years depending on the nature and severity of the offence. ANTIC (Agence Nationale des Technologies de l'Information et de la Communication) is designated as the national regulatory and enforcement authority for cybersecurity, with powers to conduct mandatory security audits of network operators and electronic service providers, operate as the root certification authority, and coordinate national cybersecurity incident response. This law is not a dedicated data protection statute. Cameroon subsequently enacted Law No. 2024/017 of 23 December 2024, which establishes a standalone personal data protection regime and will, over time, supersede the data protection provisions embedded in this law. The 2010 law remains in force for its cybercrime and cybersecurity provisions. Original language: French. An official English translation is published by ANTIC on its website.
- Operators must retain electronic communications and traffic data for ten years and disclose it to competent authorities on request
- Data protection provisions require operators to protect personal data and user privacy but do not establish a standalone data protection regime or dedicated authority
- Criminal offences (ss. 60 - 89) include unauthorised access to computer systems, data manipulation, identity theft, online fraud, child sexual abuse material, and hate speech communicated electronically
- ANTIC serves as national cybersecurity regulator with powers of mandatory audit, root certification authority functions, and incident coordination
- Penalties range from fines to custodial sentences of up to 20 years depending on offence severity
- Cross-border data obligations apply to operators with connections into Cameroonian networks regardless of country of establishment
- Note: data protection provisions have been superseded by the standalone Law No. 2024/017 of 23 December 2024 (see cm-pdpa-2024)