Enonchong Chambers Lawyers, Douala

Law No. 2024/017: what your business had to do by 23 June 2026

Cameroon's first dedicated data protection statute set a compliance deadline of 23 June 2026. That date has passed. The obligations apply whether or not the regulator has begun to enforce them.

Law No. 2024/017 of 23 December 2024 on the protection of personal data is the first statute of its kind in Cameroon. It set a compliance deadline of 23 June 2026. That date has passed, and every business processing personal data in Cameroon is now formally within scope.

Who is covered

The Law applies to the processing of personal data of individuals established, resident or in transit in Cameroon. Processing is defined broadly and includes collection, recording, organization, storage, adaptation, retrieval, dissemination, transmission, alignment, blocking, deletion and transfer. A business does not need to be a technology company to be covered. An employer holding employee records, a clinic holding patient files, a school holding student records and a store running a loyalty program are all processing personal data.

What the Law requires

  • A valid basis for processing, and where consent is relied on, consent that meets the conditions the Law sets.
  • A published privacy policy setting out what is processed and why.
  • Conditions on cross-border transfers. Data leaving Cameroon must satisfy the Law's requirements, and prior authorization is required in specified cases. This is the point most often overlooked by businesses using cloud services hosted abroad, which is to say most businesses.
  • Security measures appropriate to the data, with a higher standard for sensitive data. Health data falls into this category.
  • Prior authorization from the Data Protection Authority for certain categories of processing.
  • A certified data protection officer where processing is carried out on a large scale.

The regulator

The Law provides for a Data Protection Authority. Whether it has been set up, and whether implementing regulations have been issued, should be confirmed at the time of any compliance assessment, since the situation has been developing. The obligations themselves do not wait for the regulator: they have applied since the compliance date, and a business that treats an absent enforcement authority as an absent obligation is accumulating exposure rather than avoiding it.

The surrounding framework

Law No. 2024/017 does not stand alone. Law No. 2010/012 governs cybersecurity and cybercrime, Law No. 2010/013 governs electronic communications, and Law No. 2010/021 governs electronic commerce. Banking secrecy is governed by Law No. 2003/004. CEMAC Regulation 01/20/CEMAC/UMAC/COBAC grants deletion rights to banking customers. The Preamble to the Constitution protects privacy.

A practical order of work

  1. Map what personal data the business holds, where it came from and where it is stored
  2. Identify every transfer outside Cameroon, including cloud hosting, group companies and outsourced payroll
  3. Establish the basis for each processing operation
  4. Publish a privacy policy that matches what actually happens
  5. Put processing agreements in place with vendors who handle data on the business's behalf
  6. Decide whether the scale of processing requires a designated officer
  7. Document the decisions taken, since the ability to demonstrate compliance is itself part of compliance
Contact

Speak with an attorney

Enonchong Chambers meets with clients at its offices at 305 rue Alfred Saker in Akwa, Douala. Correspondence in English or French is answered in the language it was written in.