Cameroon
Central Africa
Cameroon's data protection landscape is in transition between two instruments. For over a decade, personal data protection sat incidentally within Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercriminality, a cybersecurity-focused statute that obliged electronic communications operators to protect users' personal data, mandated ten-year retention of connection and traffic data, criminalised identity theft and unlawful interception, and designated the Agence Nationale des Technologies de l'Information et de la Communication (ANTIC) as the cybersecurity regulator. That law established no standalone data protection regime and no dedicated authority. That changed with Law No. 2024/017 of 23 December 2024 on Personal Data Protection, Cameroon's first comprehensive, dedicated data protection statute, which over time supersedes the data protection provisions embedded in the 2010 law. The 2024 Act applies to processing carried out in Cameroon and to processing directed at persons in Cameroon, with an unusually broad reach extending even to individuals in transit. It sets consent as the primary lawful basis (opt-in, specific, informed, freely given), recognises alternative bases, imposes the full set of principles (lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, security), and grants rights of access, rectification, erasure, and objection. Sensitive categories, including racial, ethnic, linguistic or regional origin, political opinions, religious beliefs, genetic, biometric, and health data, and sexual orientation, attract strict controls. The key institutional gap is enforcement. The 2024 Act provides for an independent Personal Data Protection Authority whose composition is to be set by Presidential decree; as at enactment that authority had not been constituted, leaving ANTIC as the only authority currently on file. Controllers were given an 18-month compliance grace period ending 23 June 2026. With two instruments documented and a named regulator, Cameroon is comparatively well-covered, but the dedicated data protection authority's actual establishment is the decisive outstanding step.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 2 | 0 | ◐ |
| AI Governance | 1 | 0 | ◐ |
| Fintech | 2 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 2 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 0 | 0 | ○ |
● Covered ◐ Partially covered ○ Not yet covered
Constitution of the Republic of Cameroon (Law No. 96-06 of 18 January 1996), Preamble (Privacy of correspondence; freedom of communication, expression and the press)
Enacted 18 Jan 1996
Règlement n° 04/18/CEMAC/UMAC/COBAC du 21 décembre 2018 relatif aux services de paiement dans la CEMAC (CEMAC Regulation No. 04/18 of 21 December 2018 on Payment Services)
Enacted 21 Dec 2018
Règlement n° 03/16/CEMAC/UMAC/CM du 21 décembre 2016 relatif aux systèmes, moyens et incidents de paiement (CEMAC Regulation No. 03/16 of 21 December 2016 on Payment Systems, Means and Incidents)
Enacted 21 Dec 2016
Stratégie Nationale d'Intelligence Artificielle (SNIA) du Cameroun (National Artificial Intelligence Strategy of Cameroon)
Enacted 7 Jul 2025
Loi n° 2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité (Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercriminality)
Enacted 21 Dec 2010
Law No. 2024/017 of 23 December 2024 relating to Personal Data Protection
Enacted 23 Dec 2024
The dedicated Personal Data Protection Authority created by the 2024 Act had not been constituted by Presidential decree as at the records on file, so there is currently no dedicated supervisory enforcement; ANTIC's remit is cybersecurity, not data protection. The interaction and transition between the 2010 cyber law and the 2024 Act also remains to be worked out in practice.