What Is Law No. 2024/017 of 23 December 2024 on the Protection of Personal Data?
In the 28 August 2026 review, Cameroon has an enacted general data-protection statute: Law No. 2024/017 of 23 December 2024 on the protection of personal data. The Presidency publishes the law and a certified copy of the enacted text. Articles 1–2 establish broad coverage of public and private processing, persons established, resident, or in transit in Cameroon, Cameroon-established controllers and processors, and processing where Cameroonian law applies under international law. Article 75 repeals contrary prior provisions. The law provides a substantial data-subject rights framework, including information, access, rectification, completion, updating, locking, deletion, objection, restriction, portability, automated-decision safeguards, post-mortem protections, urgent judicial measures, and compensation for serious infringement. Current implementation remains partly unresolved. Article 53 creates an independent Personal Data Protection Authority, but its creation, organization, and functioning depend on a presidential decree. No such decree, official operational complaint portal, or implementing regulation specifying rights-request deadlines and modalities was located.
At a glance
- Full name
- Law No. 2024/017 of 23 December 2024 on the Protection of Personal Data
- Short code
- Law No. 2024/017
- Jurisdiction
- Cameroon
- Enacted
- 2024
- Last major update
- The 18-month compliance period under Article 73 elapsed on 23 June 2026; no later official amending statute was located, and no official decree establishing the Authority’s organization and functioning was located
- Regulator
- Personal Data Protection Authority provided for by Law No. 2024/017; no official operational complaint portal located
- Private right of action
- Yes
- Statutory citation
- Law No. 2024/017 of 23 December 2024 on the protection of personal data
Scope, who Law No. 2024/017 covers
Protected data
Data subject rights
Right to information at collection, including controller identity, purposes, categories, recipients, whether answering is optional, the possibility of refusing to appear in a file, and available rights
Right of access to processing information, confirmation of processing, personal data, available source information, purposes, categories, recipients, and an intelligible copy
Right to rectification, completion, updating, locking, or deletion of inaccurate or incomplete data
Right to erasure or cessation of dissemination where data are no longer necessary, consent is invalid, withdrawn, or expired, no legal basis exists, or another statutory ground applies
Right to object at any time to special-category processing, direct prospecting, or other statutory grounds; commercial-prospecting objection bars further use for that purpose
Right to free portability in a structured, commonly used, machine-readable format, including direct controller-to-controller transmission where technically possible
Right to restriction where accuracy or purpose is contested
Right to object to decisions based exclusively on automated processing, including profiling, together with human intervention, an opportunity to express a view, and the right to contest the decision
Post-mortem protections, including heirs’ ability to request updating of the deceased person’s information at the controller’s expense
Right to seek urgent judicial measures and compensation for serious infringement
Notable features
Cameroon has moved from a narrower cybersecurity and cybercrime framework to an enacted omnibus personal-data statute. The law combines broad rights with prior authorization, special restrictions for sensitive and banking data, a formal foreign-transfer authorization regime, and extensive administrative and criminal sanctions. Article 47 delegates rights-request deadlines and modalities to regulations, but no official implementing regulation specifying those periods was located.
Enforcement & penalties
Penalties: Article 54 permits a compliance notice of up to 10 days, followed by an injunction with an astreinte of up to 100,000 CFA francs per day. Article 55 provides 5–50 million CFA francs for processing without prior authorization; Article 60, 10–50 million for transferring data to a third country without prior Authority authorization; Article 61, 10–100 million for breaching applicable cahier des charges obligations. Article 63 provides 2–5 years’ imprisonment and 200,000–5 million CFA francs for fraudulent, unfair, or unlawful collection or access. Article 65 provides 3–10 years and 1–20 million for profiling. Article 69 provides 3–10 years and 2–20 million for unlawful international transfer. Criminally liable legal entities may receive fines of 50 million–1 billion CFA francs.
Private right of action: The statute provides urgent judicial relief and compensation for serious infringement, in addition to the complaint route to the Personal Data Protection Authority. No fixed deadline located governs filing a complaint, responding to a rights request, completing an Authority investigation, or resolving the complaint.
Relevance to data brokers
No official Cameroon source located a data-broker-specific, people-search-specific, public-record-specific, delisting, or de-indexing procedure. A broker holding personal data would ordinarily fall within the general controller or processor regime, including access, correction, updating, locking, deletion, cessation of dissemination, objection to prospecting, restriction, portability, and complaint routes.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Cameroon have a comprehensive personal-data-protection law?+
Yes. Law No. 2024/017 of 23 December 2024 is an enacted general data-protection statute covering public and private processing. The earlier Law No. 2010/012 remains relevant for narrower cybersecurity and cybercrime provisions.
What rights does Cameroon’s data-protection law provide?+
The law provides information, access, rectification, completion, updating, locking, deletion, objection, restriction, portability, protection against specified exclusively automated decisions, post-mortem protections, urgent judicial relief, and compensation for serious infringement.
Can I ask a Cameroonian data broker to delete my information?+
A broker would ordinarily fall within the general controller or processor regime. No data-broker-specific or public-record-specific deletion procedure was located.
Official sources & citations
Other international privacy regimes
Law No. 2024/017 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
