🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
CM · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 7 sources retrieved model claude-sonnet-5 ·

Cameroon

CM schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 8 claims · 7 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
8Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive statute appears to have been adopted in H2 2024 per secondary sources, but the exact promulgation number, gazette citation, and confirmation that the new Data Protection Authority is operationally staffed and receiving filings were not found in available research.

Primary frameworkCameroon data protection statute (adopted/enacted H2 2024, per secondary reporting) alongside prior Law No. 2010/012 of 21 December 2010 relating to Cybersecurity and Cybercriminality
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established under the new law; operational status unconfirmed)
Traffic-light rationale — AmberA comprehensive statute appears to have been adopted in H2 2024 per secondary sources, but the exact promulgation number, gazette citation, and confirmation that the new Data Protection Authority is operationally staffed and receiving filings were not found in available research.

Sub-modules (5)

Regulator And AuthorityAmber

The law (as drafted) establishes a National Authority for the Protection of Personal Data tasked with protecting data subjects' rights and freedoms.

Claims: CLM-CM-1a2b3c4d

Act And InstrumentsAmber

Instruments identified: (i) the new personal data protection law adopted in H2 2024 (exact number unconfirmed); (ii) the pre-existing Law No. 2010/012 of 21 December 2010 relating to Cybersecurity and Cybercriminality, which historically touched on data-related offences.

Claims: CLM-CM-2b3c4d5e, CLM-CM-3c4d5e6f

Material ScopeAmber

The draft law's definitional apparatus (personal data, biometric data, genetic data, sensitive data, controller, processor, personal data breach, SCCs) indicates a GDPR-adjacent material scope, though final enacted definitions were not independently verified.

Claims: CLM-CM-4d5e6f7a

Territorial ScopeAmber

The draft law extends extraterritorially to processing of personal data of Cameroon-resident individuals and Cameroonian nationals, including by subcontractors not established in Cameroon where the controller is established there.

Claims: CLM-CM-5e6f7a8b

Regulator Registration And FilingRed

No confirmed evidence of a live registration/filing portal or published filing rules for controllers was found.

Absence provenance: not recorded. Searched: Cameroon data protection authority registration filing controllers, ANTIC Cameroon cybersecurity law personal data provisions.

Category narrative143 words

Cameroon moved from a sector-adjacent cybersecurity framework (Law No. 2010/012 of 21 December 2010 relating to Cybersecurity and Cybercriminality) to a dedicated data-protection statute. A draft law circulated for public comment in 2023 by the Ministry of Posts and Telecommunications (via the PATNUC digital-transformation project), was subsequently introduced in the Senate in late 2024, and a draft data-protection bill was reported adopted by Parliament. IAPP's Global Privacy Law and DPA Directory update lists Cameroon among jurisdictions that welcomed a new comprehensive data privacy law in the second half of 2024. The draft/enacted framework provides for a new National Authority for the Protection of Personal Data, but confirmation of its operational status (appointed members, registered filings, published decisions) could not be retrieved from available sources, so this module is scored amber pending primary-source confirmation of the gazetted law number and the authority's operational stand-up.

Sources and claims (5)
  1. ProbableOneTrust DataGuidanceCameroon's data protection law provides for the establishment of a National Authority for the Protection of Personal Data responsible for protecting the rights and freedoms of natural persons regarding the processing of their personal data.
  2. ProbableIAPPCameroon adopted a new comprehensive data privacy law in the second half of 2024.
  3. UncertainOneTrust DataGuidance (legal research repository)Cameroon's Law No. 2010/012 of 21 December 2010 relates to cybersecurity and cybercriminality and pre-dates the dedicated 2024 data protection statute.
  4. ProbableOneTrust DataGuidanceThe Cameroon data protection law's definitional framework covers personal data, biometric data, genetic data, sensitive data, data subject, controller, processor, processing, personal data breach, and standard contractual clauses.
  5. ProbableOneTrust DataGuidanceThe law's territorial reach covers processing of personal data of individuals residing in Cameroon, processing by subcontractors not established in Cameroon where the controller is established there, and processing of Cameroonian nationals' data where Cameroonian law applies under international law.

#

Special-category definitions are evidenced from the 2023 draft-law consultation summary; lawful bases, consent standards, and anonymisation rules are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberSpecial-category definitions are evidenced from the 2023 draft-law consultation summary; lawful bases, consent standards, and anonymisation rules are unconfirmed.

Sub-modules (4)

Lawful BasesRed

No confirmed enumeration of lawful bases equivalent to GDPR Art 6 was located in available sources.

Absence provenance: not recorded. Searched: Cameroon data protection law lawful basis consent processing, Cameroon personal data protection law 2024 provisions.

Special CategoriesAmber

The draft law defines biometric data, genetic data, and sensitive data as distinct categories, indicating a special-category regime, though specific processing restrictions were not retrievable.

Claims: CLM-CM-6f7a8b9c

Pseudonymisation And AnonymisationRed

No confirmed provisions on pseudonymisation or anonymisation safe-harbours were located.

Absence provenance: not recorded. Searched: Cameroon data protection law pseudonymisation anonymisation.

Category narrative43 words

The draft/enacted law defines and appears to regulate special categories such as biometric data and genetic data, and references 'sensitive data' as a defined term. Confirmation of the enumerated lawful bases, consent thresholds, and any pseudonymisation/anonymisation safe-harbour was not found in available sources.

Sources and claims (1)
  1. ProbableOneTrust DataGuidanceCameroon's data protection law defines 'biometric data,' 'genetic data,' and 'sensitive data' as distinct categories subject to specific rules.

#

No sub-module could be populated beyond a generic reference to rights protection; specific rights and deadlines are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — RedNo sub-module could be populated beyond a generic reference to rights protection; specific rights and deadlines are unconfirmed.

Sub-modules (5)

Access RightRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection law subject access request right.

Rectification And ErasureRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection law right to erasure rectification.

Restriction And ObjectionRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection law right to object restriction processing.

Data PortabilityRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection law data portability right.

Deadlines And Response WindowsRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection law response deadline data subject request.

Category narrative37 words

Available sources reference the establishment of a Data Protection Authority tasked with protecting individuals' rights and freedoms with respect to processing, implying baseline data subject rights, but no enumerated access/rectification/erasure/portability provisions or statutory response deadlines were retrievable.

#

Accountability principles are evidenced from the 2023 draft-law summary; DPIA triggers, DPO thresholds, ROPA, breach notification specifics and retention rules are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberAccountability principles are evidenced from the 2023 draft-law summary; DPIA triggers, DPO thresholds, ROPA, breach notification specifics and retention rules are unconfirmed.

Sub-modules (7)

Accountability And DpiaAmber

The law's stated principles include purpose limitation, retention limitation, transparency, confidentiality, accessibility, and appropriate technical/organizational security measures proportionate to risk, consistent with an accountability-style regime, though a DPIA trigger threshold was not independently confirmed.

Claims: CLM-CM-7a8b9c0d

Dpo RequirementsRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection law DPO appointment threshold.

Ropa RequirementsRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection law records of processing register.

Joint Controller ArrangementsRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection law joint controller processor obligations.

Security MeasuresAmber

The draft law requires appropriate technical and organizational measures to guarantee a level of security appropriate to the risk of processing.

Claims: CLM-CM-7a8b9c0d

Breach NotificationRed

The draft law defines 'personal data breach' as a term of art, but confirmed notification timelines/thresholds to the regulator and data subjects were not located.

Absence provenance: not recorded. Searched: Cameroon data protection law breach notification timeline.

Retention And DisposalAmber

The draft law references a 'retention limitation' principle, but specific retention periods or disposal duties were not confirmed.

Claims: CLM-CM-7a8b9c0d

Category narrative40 words

The draft law outlines general accountability principles (purpose limitation, retention limitation, transparency, confidentiality, accessibility, and appropriate technical and organizational security measures). No confirmed DPO appointment thresholds, ROPA requirements, joint-controller rules, breach-notification timelines, or retention/disposal mandates were located in available sources.

Sources and claims (1)
  1. ProbableOneTrust DataGuidanceCameroon's data protection law sets out principles for processing personal data including purpose limitation, retention limitation, transparency, confidentiality, accessibility, and appropriate technical and organizational measures to guarantee a level of security appropriate to the risk of the processing.

#

SCC/BCR transfer mechanisms are evidenced from the 2023 draft-law summary; adequacy status and localisation rules are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberSCC/BCR transfer mechanisms are evidenced from the 2023 draft-law summary; adequacy status and localisation rules are unconfirmed.

Sub-modules (6)

Transfer MechanismsAmber

The draft law provides for standard contractual clauses approved by the Data Protection Authority and binding corporate rules adopted by the importing entity as transfer mechanisms.

Claims: CLM-CM-8b9c0d1e

Adequacy ReceivedRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon adequacy decision received EU GDPR.

Adequacy GrantedRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon adequacy decision granted to other jurisdictions.

Sccs And BcrsAmber

SCCs and BCRs are referenced as available transfer mechanisms under the draft law, subject to regulator approval for SCCs.

Claims: CLM-CM-8b9c0d1e

Transfer Impact AssessmentRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection law transfer impact assessment requirement.

Data LocalisationRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data localisation requirement personal data.

Category narrative42 words

The draft law contemplates cross-border transfer mechanisms including standard contractual clauses approved by the Data Protection Authority and binding corporate rules adopted by the data importer. No confirmed adequacy decisions (received or granted), transfer impact assessment requirement, or data-localisation mandate were located.

Sources and claims (1)
  1. ProbableOneTrust DataGuidanceCameroon's data protection law provides for cross-border transfer via standard contractual clauses approved by the Data Protection Authority, signed between the exporting entity and the third-party importer, and via binding corporate rules adopted by the importing entity.

#

Absence of sectoral overlay evidence.

Traffic-light rationale — RedAbsence of sectoral overlay evidence.

Sub-modules (7)

Financial Sector OverlayRed

Not found.

Absence provenance: not recorded. Searched: Cameroon banking data protection overlay financial sector.

Health Sector OverlayRed

Not found.

Absence provenance: not recorded. Searched: Cameroon health data protection overlay.

Telecoms And EprivacyRed

Not found beyond the general cybersecurity/cybercriminality law reference.

Absence provenance: not recorded. Searched: Cameroon ePrivacy telecoms cookies law.

Employment DataRed

Not found.

Absence provenance: not recorded. Searched: Cameroon employment data protection code.

Credit And ScoringRed

Not found.

Absence provenance: not recorded. Searched: Cameroon credit scoring data protection rules.

EducationRed

Not found.

Absence provenance: not recorded. Searched: Cameroon education sector data protection rules.

InsuranceRed

Not found.

Absence provenance: not recorded. Searched: Cameroon insurance sector data protection rules.

Category narrative17 words

No sector-specific overlays (financial, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) for Cameroon were identified in available research.

#

No adtech-specific evidence located.

Traffic-light rationale — RedNo adtech-specific evidence located.

Sub-modules (6)

Cookies And TrackersRed

Not found.

Absence provenance: not recorded. Searched: Cameroon cookie consent law tracker regulation.

Dark PatternsRed

Not found.

Absence provenance: not recorded. Searched: Cameroon dark pattern prohibition consumer data.

Opt Out SignalsRed

Not found.

Absence provenance: not recorded. Searched: Cameroon global privacy control opt out signal.

Clean Rooms And DcrRed

Not found.

Absence provenance: not recorded. Searched: Cameroon data clean room regulation.

Cross Context AdvertisingRed

Not found.

Absence provenance: not recorded. Searched: Cameroon cross context advertising data sale share.

Direct MarketingRed

Not found.

Absence provenance: not recorded. Searched: Cameroon direct marketing consent suppression law.

Category narrative24 words

No confirmed cookie/tracker consent regime, dark-pattern prohibitions, opt-out signal recognition, clean-room rules, cross-context advertising rules, or direct-marketing suppression regime specific to Cameroon were located.

#

Only definitional evidence for biometric/genetic data was found; substantive governance provisions unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberOnly definitional evidence for biometric/genetic data was found; substantive governance provisions unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

Not found.

Absence provenance: not recorded. Searched: Cameroon profiling restriction automated decision.

Automated Decision Making TransparencyRed

Not found.

Absence provenance: not recorded. Searched: Cameroon automated decision making transparency right.

Ai Risk AssessmentsRed

Not found.

Absence provenance: not recorded. Searched: Cameroon AI risk assessment law.

Biometric RegimeAmber

The draft law defines biometric data as a distinct data category subject to the statute's sensitive-data provisions.

Claims: CLM-CM-6f7a8b9c

Genetic DataAmber

The draft law defines genetic data as a distinct data category subject to the statute's sensitive-data provisions.

Claims: CLM-CM-6f7a8b9c

State Surveillance CarveoutsRed

Not found.

Absence provenance: not recorded. Searched: Cameroon national security exemption data protection law.

Category narrative33 words

The draft law defines 'biometric data' and 'genetic data' as distinct categories, implying a nascent biometric/genetic-data regime, but confirmed profiling restrictions, ADM transparency rights, AI-specific risk-assessment requirements, or state-surveillance carveouts were not located.

#

No children/vulnerable-groups-specific evidence located.

Traffic-light rationale — RedNo children/vulnerable-groups-specific evidence located.

Sub-modules (5)

Age VerificationRed

Not found.

Absence provenance: not recorded. Searched: Cameroon age verification minors data law.

Minor Profiling BansRed

Not found.

Absence provenance: not recorded. Searched: Cameroon minor profiling ban law.

Education SettingsRed

Not found.

Absence provenance: not recorded. Searched: Cameroon education data protection rules students.

Dependent AdultsRed

Not found.

Absence provenance: not recorded. Searched: Cameroon dependent adults data protection.

Category narrative21 words

No confirmed age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-setting rule, or dependent-adult protection specific to Cameroon's data protection framework was located.

#

Recent legislative development is evidenced; substantive enforcement powers/penalties and enforcement track record are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberRecent legislative development is evidenced; substantive enforcement powers/penalties and enforcement track record are unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection authority powers penalties fines.

Enforcement Activity IndexRed

Not confirmed; the National Authority for the Protection of Personal Data does not appear to have a confirmed operational enforcement record yet.

Absence provenance: not recorded. Searched: Cameroon data protection authority enforcement decision fine.

Regulator Funding And CapacityRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon data protection authority budget staffing.

Collective Redress And Class ActionsRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon collective redress class action data protection.

Private Right Of ActionRed

Not confirmed.

Absence provenance: not recorded. Searched: Cameroon private right of action data protection court.

Recent Developments 180DAmber

Within the broader 2024 legislative cycle, the Cameroon Senate announced introduction of the draft Data Protection bill (reported November 2024) and a subsequent report indicated the draft bill was adopted in Parliament; IAPP's directory update lists Cameroon among jurisdictions with a new comprehensive privacy law effective in the second half of 2024. Exact gazettal date and current (August 2026) implementation status of the National Authority could not be confirmed from available sources within the 180-day recency window.

Claims: CLM-CM-2b3c4d5e

Category narrative60 words

Secondary reporting confirms legislative activity in H2 2024 (Senate introduction of the draft Data Protection bill, and a subsequent report of the bill's adoption in Parliament), consistent with IAPP's confirmation of a new Cameroon data privacy law in H2 2024. Confirmed regulator powers, maximum penalties, enforcement-activity record, funding/capacity signals, collective-redress mechanisms, and private-right-of-action provisions were not located in available sources.

No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Cameroon
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 8 claim(s), 22 source(s) in the cumulative register.