World Watch/Cameroon/Data & Privacy

Data & Privacy · Cameroon

Data protection & privacy laws in Cameroon (2026)

Comprehensive lawLaw No. 2024/017 of 23 December 2024 relating to personal data protection in Cameroon; supplemented by Law No. 2010/012 of 21 December 2010 on Cybersecurity and Cybercriminality. Supervisory authority: Personal Data Protection Authority (Autorité de protection des données à caractère personnel) — mandated by the 2024 law but not yet operationally established as of mid-2026.Country index 76 · B+

Cameroon shaded by its data & privacy status

Cameroon enacted a comprehensive, GDPR-inspired personal data protection law on 23 December 2024 (Law No. 2024/017), becoming the 38th African country to adopt standalone data-protection legislation. The law introduced a broad set of data-subject rights and controller/processor obligations, with an 18-month compliance grace period expiring 23 June 2026. A dedicated supervisory authority is mandated under the law but had not yet become operational at time of research.

Key points

Enacted comprehensive law

Law No. 2024/017 was signed on 23 December 2024 and published on the Presidency of the Republic's official portal. It supersedes the fragmented privacy provisions of the 2010 Cybersecurity Law and establishes a standalone, comprehensive personal data protection regime.

Compliance grace period

The law grants controllers and processors an 18-month transition period from enactment, placing the full-enforcement deadline at 23 June 2026. Organisations are expected to audit and align their data-processing operations before that date.

Supervisory authority

The law creates the Personal Data Protection Authority (Autorité de protection des données à caractère personnel), responsible for enforcement, authorisations, complaints handling, and cross-border transfer approvals. The authority was not yet operationally established as of mid-2026; ANTIC (National Agency for Information and Communication Technologies) continues to exercise interim oversight over digital/telecom services.

Data subject rights

Data subjects hold rights to be informed, access, rectify, erase, restrict, object to, and port their data — mirroring GDPR. Uniquely, heirs may exercise access and update rights on behalf of deceased data subjects at the controller's expense.

Sensitive data and controller obligations

Processing of special categories — including health, biometrics, genetics, racial/ethnic origin, religion, political/trade-union opinions, and criminal records — is prohibited without explicit consent or another legal basis. Controllers must conduct Data Protection Impact Assessments, maintain records of processing, and implement appropriate security measures.

Penalties

Non-compliance can attract fines of up to 1 billion CFA francs (≈ USD 1.6 million) and criminal imprisonment for responsible executives. The law creates personal liability for senior officers of infringing organisations.

Cameroon - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →