CM

Cameroon

Central Africa

6Instruments
0Cases
3Regulators
80%Coverage
Overview

Cameroon's data protection landscape is in transition between two instruments. For over a decade, personal data protection sat incidentally within Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercriminality, a cybersecurity-focused statute that obliged electronic communications operators to protect users' personal data, mandated ten-year retention of connection and traffic data, criminalised identity theft and unlawful interception, and designated the Agence Nationale des Technologies de l'Information et de la Communication (ANTIC) as the cybersecurity regulator. That law established no standalone data protection regime and no dedicated authority. That changed with Law No. 2024/017 of 23 December 2024 on Personal Data Protection, Cameroon's first comprehensive, dedicated data protection statute, which over time supersedes the data protection provisions embedded in the 2010 law. The 2024 Act applies to processing carried out in Cameroon and to processing directed at persons in Cameroon, with an unusually broad reach extending even to individuals in transit. It sets consent as the primary lawful basis (opt-in, specific, informed, freely given), recognises alternative bases, imposes the full set of principles (lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, security), and grants rights of access, rectification, erasure, and objection. Sensitive categories, including racial, ethnic, linguistic or regional origin, political opinions, religious beliefs, genetic, biometric, and health data, and sexual orientation, attract strict controls. The key institutional gap is enforcement. The 2024 Act provides for an independent Personal Data Protection Authority whose composition is to be set by Presidential decree; as at enactment that authority had not been constituted, leaving ANTIC as the only authority currently on file. Controllers were given an 18-month compliance grace period ending 23 June 2026. With two instruments documented and a named regulator, Cameroon is comparatively well-covered, but the dedicated data protection authority's actual establishment is the decisive outstanding step.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection20
AI Governance10
Fintech20
Cybercrime10
Digital Rights20
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
cm-const-privacy·Act

Constitution of the Republic of Cameroon (Law No. 96-06 of 18 January 1996), Preamble (Privacy of correspondence; freedom of communication, expression and the press)

CameroonDigital RightsIn Force
Verified

Enacted 18 Jan 1996

cemac-fintech-paymentservices-2018·Regulation

Règlement n° 04/18/CEMAC/UMAC/COBAC du 21 décembre 2018 relatif aux services de paiement dans la CEMAC (CEMAC Regulation No. 04/18 of 21 December 2018 on Payment Services)

CameroonFintechIn Force
Verified

Enacted 21 Dec 2018

cemac-fintech-paymentsystems-2016·Regulation

Règlement n° 03/16/CEMAC/UMAC/CM du 21 décembre 2016 relatif aux systèmes, moyens et incidents de paiement (CEMAC Regulation No. 03/16 of 21 December 2016 on Payment Systems, Means and Incidents)

CameroonFintechIn Force
Verified

Enacted 21 Dec 2016

cm-ai-2025·Guidance

Stratégie Nationale d'Intelligence Artificielle (SNIA) du Cameroun (National Artificial Intelligence Strategy of Cameroon)

CameroonAI GovernanceProposed
Verified

Enacted 7 Jul 2025

cm-cyber-2010·Act

Loi n° 2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité (Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercriminality)

CameroonData ProtectionCybercrimeDigital RightsIn Force
Verified

Enacted 21 Dec 2010

cm-pdpa-2024·Act

Law No. 2024/017 of 23 December 2024 relating to Personal Data Protection

CameroonData ProtectionIn Force
Verified

Enacted 23 Dec 2024

Notable gaps

The dedicated Personal Data Protection Authority created by the 2024 Act had not been constituted by Presidential decree as at the records on file, so there is currently no dedicated supervisory enforcement; ANTIC's remit is cybersecurity, not data protection. The interaction and transition between the 2010 cyber law and the 2024 Act also remains to be worked out in practice.