🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
CM v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 3 failing7 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Cameroon

CM schema gdpri-v2 trajectory: not yet assessedin transition

Last updated update date not yet available · 10 categories · 8 claims · 15 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
8Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 44 sub-modules are flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A comprehensive statute appears to have been adopted in H2 2024 per secondary sources, but the exact promulgation number, gazette citation, and confirmation that the new Data Protection Authority is operationally staffed and receiving filings were not found in available research.

Primary frameworkCameroon data protection statute (adopted/enacted H2 2024, per secondary reporting) alongside prior Law No. 2010/012 of 21 December 2010 relating to Cybersecurity and Cybercriminality
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established under the new law; operational status unconfirmed)
Traffic-light rationale — AmberA comprehensive statute appears to have been adopted in H2 2024 per secondary sources, but the exact promulgation number, gazette citation, and confirmation that the new Data Protection Authority is operationally staffed and receiving filings were not found in available research.

Sub-modules (5)

Regulator And AuthorityAmber

The law (as drafted) establishes a National Authority for the Protection of Personal Data tasked with protecting data subjects' rights and freedoms.

Claims (1):

  • Cameroon's data protection law provides for the establishment of a National Authority for the Protection of Personal Data responsible for protecting the rights and freedoms of natural persons regarding the processing of their personal data.

Act And InstrumentsAmber

Instruments identified: (i) the new personal data protection law adopted in H2 2024 (exact number unconfirmed); (ii) the pre-existing Law No. 2010/012 of 21 December 2010 relating to Cybersecurity and Cybercriminality, which historically touched on data-related offences.

Claims (2):

  • Cameroon adopted a new comprehensive data privacy law in the second half of 2024.
  • Cameroon's Law No. 2010/012 of 21 December 2010 relates to cybersecurity and cybercriminality and pre-dates the dedicated 2024 data protection statute.

Material ScopeAmber

The draft law's definitional apparatus (personal data, biometric data, genetic data, sensitive data, controller, processor, personal data breach, SCCs) indicates a GDPR-adjacent material scope, though final enacted definitions were not independently verified.

Claims (1):

  • The Cameroon data protection law's definitional framework covers personal data, biometric data, genetic data, sensitive data, data subject, controller, processor, processing, personal data breach, and standard contractual clauses.

Territorial ScopeAmber

The draft law extends extraterritorially to processing of personal data of Cameroon-resident individuals and Cameroonian nationals, including by subcontractors not established in Cameroon where the controller is established there.

Claims (1):

  • The law's territorial reach covers processing of personal data of individuals residing in Cameroon, processing by subcontractors not established in Cameroon where the controller is established there, and processing of Cameroonian nationals' data where Cameroonian law applies under international law.

Regulator Registration And FilingRed

No confirmed evidence of a live registration/filing portal or published filing rules for controllers was found.

Absence provenance: unavailable. Searched: Cameroon data protection authority registration filing controllers, ANTIC Cameroon cybersecurity law personal data provisions.

Category narrative143 words

Cameroon moved from a sector-adjacent cybersecurity framework (Law No. 2010/012 of 21 December 2010 relating to Cybersecurity and Cybercriminality) to a dedicated data-protection statute. A draft law circulated for public comment in 2023 by the Ministry of Posts and Telecommunications (via the PATNUC digital-transformation project), was subsequently introduced in the Senate in late 2024, and a draft data-protection bill was reported adopted by Parliament. IAPP's Global Privacy Law and DPA Directory update lists Cameroon among jurisdictions that welcomed a new comprehensive data privacy law in the second half of 2024. The draft/enacted framework provides for a new National Authority for the Protection of Personal Data, but confirmation of its operational status (appointed members, registered filings, published decisions) could not be retrieved from available sources, so this module is scored amber pending primary-source confirmation of the gazetted law number and the authority's operational stand-up.

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — Cameroon's data protection law provides for the establishment of a National Authority for the Protection of Personal Data responsible for protecting the rights and freedoms of natural persons regarding the processing of their personal data.observed
  2. UncertainIAPP — Cameroon adopted a new comprehensive data privacy law in the second half of 2024.observed
  3. UncertainOneTrust DataGuidance (legal research repository) — Cameroon's Law No. 2010/012 of 21 December 2010 relates to cybersecurity and cybercriminality and pre-dates the dedicated 2024 data protection statute.observed
  4. UncertainOneTrust DataGuidance — The Cameroon data protection law's definitional framework covers personal data, biometric data, genetic data, sensitive data, data subject, controller, processor, processing, personal data breach, and standard contractual clauses.observed
  5. UncertainOneTrust DataGuidance — The law's territorial reach covers processing of personal data of individuals residing in Cameroon, processing by subcontractors not established in Cameroon where the controller is established there, and processing of Cameroonian nationals' data where Cameroonian law applies under international law.observed

#

Special-category definitions are evidenced from the 2023 draft-law consultation summary; lawful bases, consent standards, and anonymisation rules are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberSpecial-category definitions are evidenced from the 2023 draft-law consultation summary; lawful bases, consent standards, and anonymisation rules are unconfirmed.

Sub-modules (4)

Lawful BasesRed

No confirmed enumeration of lawful bases equivalent to GDPR Art 6 was located in available sources.

Absence provenance: unavailable. Searched: Cameroon data protection law lawful basis consent processing, Cameroon personal data protection law 2024 provisions.

Special CategoriesAmber

The draft law defines biometric data, genetic data, and sensitive data as distinct categories, indicating a special-category regime, though specific processing restrictions were not retrievable.

Claims (1):

  • Cameroon's data protection law defines 'biometric data,' 'genetic data,' and 'sensitive data' as distinct categories subject to specific rules.

Pseudonymisation And AnonymisationRed

No confirmed provisions on pseudonymisation or anonymisation safe-harbours were located.

Absence provenance: unavailable. Searched: Cameroon data protection law pseudonymisation anonymisation.

Category narrative43 words

The draft/enacted law defines and appears to regulate special categories such as biometric data and genetic data, and references 'sensitive data' as a defined term. Confirmation of the enumerated lawful bases, consent thresholds, and any pseudonymisation/anonymisation safe-harbour was not found in available sources.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — Cameroon's data protection law defines 'biometric data,' 'genetic data,' and 'sensitive data' as distinct categories subject to specific rules.observed

#

No sub-module could be populated beyond a generic reference to rights protection; specific rights and deadlines are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — Not assessedNo sub-module could be populated beyond a generic reference to rights protection; specific rights and deadlines are unconfirmed.

Sub-modules (5)

Access RightRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection law subject access request right.

Rectification And ErasureRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection law right to erasure rectification.

Restriction And ObjectionRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection law right to object restriction processing.

Data PortabilityRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection law data portability right.

Deadlines And Response WindowsRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection law response deadline data subject request.

Category narrative37 words

Available sources reference the establishment of a Data Protection Authority tasked with protecting individuals' rights and freedoms with respect to processing, implying baseline data subject rights, but no enumerated access/rectification/erasure/portability provisions or statutory response deadlines were retrievable.

#

Accountability principles are evidenced from the 2023 draft-law summary; DPIA triggers, DPO thresholds, ROPA, breach notification specifics and retention rules are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberAccountability principles are evidenced from the 2023 draft-law summary; DPIA triggers, DPO thresholds, ROPA, breach notification specifics and retention rules are unconfirmed.

Sub-modules (7)

Accountability And DpiaAmber

The law's stated principles include purpose limitation, retention limitation, transparency, confidentiality, accessibility, and appropriate technical/organizational security measures proportionate to risk, consistent with an accountability-style regime, though a DPIA trigger threshold was not independently confirmed.

Claims (1):

  • Cameroon's data protection law sets out principles for processing personal data including purpose limitation, retention limitation, transparency, confidentiality, accessibility, and appropriate technical and organizational measures to guarantee a level of security appropriate to the risk of the processing.

Dpo RequirementsRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection law DPO appointment threshold.

Ropa RequirementsRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection law records of processing register.

Joint Controller ArrangementsRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection law joint controller processor obligations.

Security MeasuresAmber

The draft law requires appropriate technical and organizational measures to guarantee a level of security appropriate to the risk of processing.

Claims (1):

  • Cameroon's data protection law sets out principles for processing personal data including purpose limitation, retention limitation, transparency, confidentiality, accessibility, and appropriate technical and organizational measures to guarantee a level of security appropriate to the risk of the processing.

Breach NotificationRed

The draft law defines 'personal data breach' as a term of art, but confirmed notification timelines/thresholds to the regulator and data subjects were not located.

Absence provenance: unavailable. Searched: Cameroon data protection law breach notification timeline.

Retention And DisposalAmber

The draft law references a 'retention limitation' principle, but specific retention periods or disposal duties were not confirmed.

Claims (1):

  • Cameroon's data protection law sets out principles for processing personal data including purpose limitation, retention limitation, transparency, confidentiality, accessibility, and appropriate technical and organizational measures to guarantee a level of security appropriate to the risk of the processing.
Category narrative40 words

The draft law outlines general accountability principles (purpose limitation, retention limitation, transparency, confidentiality, accessibility, and appropriate technical and organizational security measures). No confirmed DPO appointment thresholds, ROPA requirements, joint-controller rules, breach-notification timelines, or retention/disposal mandates were located in available sources.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — Cameroon's data protection law sets out principles for processing personal data including purpose limitation, retention limitation, transparency, confidentiality, accessibility, and appropriate technical and organizational measures to guarantee a level of security appropriate to the risk of the processing.observed

#

SCC/BCR transfer mechanisms are evidenced from the 2023 draft-law summary; adequacy status and localisation rules are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberSCC/BCR transfer mechanisms are evidenced from the 2023 draft-law summary; adequacy status and localisation rules are unconfirmed.

Sub-modules (6)

Transfer MechanismsAmber

The draft law provides for standard contractual clauses approved by the Data Protection Authority and binding corporate rules adopted by the importing entity as transfer mechanisms.

Claims (1):

  • Cameroon's data protection law provides for cross-border transfer via standard contractual clauses approved by the Data Protection Authority, signed between the exporting entity and the third-party importer, and via binding corporate rules adopted by the importing entity.

Adequacy ReceivedRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon adequacy decision received EU GDPR.

Adequacy GrantedRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon adequacy decision granted to other jurisdictions.

Sccs And BcrsAmber

SCCs and BCRs are referenced as available transfer mechanisms under the draft law, subject to regulator approval for SCCs.

Claims (1):

  • Cameroon's data protection law provides for cross-border transfer via standard contractual clauses approved by the Data Protection Authority, signed between the exporting entity and the third-party importer, and via binding corporate rules adopted by the importing entity.

Transfer Impact AssessmentRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection law transfer impact assessment requirement.

Data LocalisationRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data localisation requirement personal data.

Category narrative42 words

The draft law contemplates cross-border transfer mechanisms including standard contractual clauses approved by the Data Protection Authority and binding corporate rules adopted by the data importer. No confirmed adequacy decisions (received or granted), transfer impact assessment requirement, or data-localisation mandate were located.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — Cameroon's data protection law provides for cross-border transfer via standard contractual clauses approved by the Data Protection Authority, signed between the exporting entity and the third-party importer, and via binding corporate rules adopted by the importing entity.observed

#

Absence of sectoral overlay evidence.

Traffic-light rationale — Not assessedAbsence of sectoral overlay evidence.

Sub-modules (7)

Financial Sector OverlayRed

Not found.

Absence provenance: unavailable. Searched: Cameroon banking data protection overlay financial sector.

Health Sector OverlayRed

Not found.

Absence provenance: unavailable. Searched: Cameroon health data protection overlay.

Telecoms And EprivacyRed

Not found beyond the general cybersecurity/cybercriminality law reference.

Absence provenance: unavailable. Searched: Cameroon ePrivacy telecoms cookies law.

Employment DataRed

Not found.

Absence provenance: unavailable. Searched: Cameroon employment data protection code.

Credit And ScoringRed

Not found.

Absence provenance: unavailable. Searched: Cameroon credit scoring data protection rules.

EducationRed

Not found.

Absence provenance: unavailable. Searched: Cameroon education sector data protection rules.

InsuranceRed

Not found.

Absence provenance: unavailable. Searched: Cameroon insurance sector data protection rules.

Category narrative17 words

No sector-specific overlays (financial, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) for Cameroon were identified in available research.

#

No adtech-specific evidence located.

Traffic-light rationale — Not assessedNo adtech-specific evidence located.

Sub-modules (6)

Cookies And TrackersRed

Not found.

Absence provenance: unavailable. Searched: Cameroon cookie consent law tracker regulation.

Dark PatternsRed

Not found.

Absence provenance: unavailable. Searched: Cameroon dark pattern prohibition consumer data.

Opt Out SignalsRed

Not found.

Absence provenance: unavailable. Searched: Cameroon global privacy control opt out signal.

Clean Rooms And DcrRed

Not found.

Absence provenance: unavailable. Searched: Cameroon data clean room regulation.

Cross Context AdvertisingRed

Not found.

Absence provenance: unavailable. Searched: Cameroon cross context advertising data sale share.

Direct MarketingRed

Not found.

Absence provenance: unavailable. Searched: Cameroon direct marketing consent suppression law.

Category narrative24 words

No confirmed cookie/tracker consent regime, dark-pattern prohibitions, opt-out signal recognition, clean-room rules, cross-context advertising rules, or direct-marketing suppression regime specific to Cameroon were located.

#

Only definitional evidence for biometric/genetic data was found; substantive governance provisions unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberOnly definitional evidence for biometric/genetic data was found; substantive governance provisions unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

Not found.

Absence provenance: unavailable. Searched: Cameroon profiling restriction automated decision.

Automated Decision Making TransparencyRed

Not found.

Absence provenance: unavailable. Searched: Cameroon automated decision making transparency right.

Ai Risk AssessmentsRed

Not found.

Absence provenance: unavailable. Searched: Cameroon AI risk assessment law.

Biometric RegimeAmber

The draft law defines biometric data as a distinct data category subject to the statute's sensitive-data provisions.

Claims (1):

  • Cameroon's data protection law defines 'biometric data,' 'genetic data,' and 'sensitive data' as distinct categories subject to specific rules.

Genetic DataAmber

The draft law defines genetic data as a distinct data category subject to the statute's sensitive-data provisions.

Claims (1):

  • Cameroon's data protection law defines 'biometric data,' 'genetic data,' and 'sensitive data' as distinct categories subject to specific rules.

State Surveillance CarveoutsRed

Not found.

Absence provenance: unavailable. Searched: Cameroon national security exemption data protection law.

Category narrative33 words

The draft law defines 'biometric data' and 'genetic data' as distinct categories, implying a nascent biometric/genetic-data regime, but confirmed profiling restrictions, ADM transparency rights, AI-specific risk-assessment requirements, or state-surveillance carveouts were not located.

#

No children/vulnerable-groups-specific evidence located.

Traffic-light rationale — Not assessedNo children/vulnerable-groups-specific evidence located.

Sub-modules (5)

Age VerificationRed

Not found.

Absence provenance: unavailable. Searched: Cameroon age verification minors data law.

Minor Profiling BansRed

Not found.

Absence provenance: unavailable. Searched: Cameroon minor profiling ban law.

Education SettingsRed

Not found.

Absence provenance: unavailable. Searched: Cameroon education data protection rules students.

Dependent AdultsRed

Not found.

Absence provenance: unavailable. Searched: Cameroon dependent adults data protection.

Category narrative21 words

No confirmed age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-setting rule, or dependent-adult protection specific to Cameroon's data protection framework was located.

#

Recent legislative development is evidenced; substantive enforcement powers/penalties and enforcement track record are unconfirmed.

Primary frameworkCameroon data protection statute (2024, exact citation unconfirmed)
Supervisory authorityNational Authority for the Protection of Personal Data (proposed/established; status unconfirmed)
Traffic-light rationale — AmberRecent legislative development is evidenced; substantive enforcement powers/penalties and enforcement track record are unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection authority powers penalties fines.

Enforcement Activity IndexRed

Not confirmed; the National Authority for the Protection of Personal Data does not appear to have a confirmed operational enforcement record yet.

Absence provenance: unavailable. Searched: Cameroon data protection authority enforcement decision fine.

Regulator Funding And CapacityRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon data protection authority budget staffing.

Collective Redress And Class ActionsRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon collective redress class action data protection.

Private Right Of ActionRed

Not confirmed.

Absence provenance: unavailable. Searched: Cameroon private right of action data protection court.

Recent Developments 180DAmber

Within the broader 2024 legislative cycle, the Cameroon Senate announced introduction of the draft Data Protection bill (reported November 2024) and a subsequent report indicated the draft bill was adopted in Parliament; IAPP's directory update lists Cameroon among jurisdictions with a new comprehensive privacy law effective in the second half of 2024. Exact gazettal date and current (August 2026) implementation status of the National Authority could not be confirmed from available sources within the 180-day recency window.

Claims (1):

  • Cameroon adopted a new comprehensive data privacy law in the second half of 2024.
Category narrative60 words

Secondary reporting confirms legislative activity in H2 2024 (Senate introduction of the draft Data Protection bill, and a subsequent report of the bill's adoption in Parliament), consistent with IAPP's confirmation of a new Cameroon data privacy law in H2 2024. Confirmed regulator powers, maximum penalties, enforcement-activity record, funding/capacity signals, collective-redress mechanisms, and private-right-of-action provisions were not located in available sources.

No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 3 failing check(s).

schema_validpass
min_architecture_patterns0
min_red_flags0
min_controls0
worked_examples_count0
decision_tree_nodes0
counterparty_diligence_questions0
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
board_briefing_presentFAIL
every_practical_object_has_source_idFAIL
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Cameroon
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 8 claim(s) (8 category placement(s)), 15 source(s) in the cumulative register.

Audit trail

Machine checkChallenged on 29 Sep 2026: nothing tested (no claim on this page was eligible for an automated test). An automated, adversarial test run by a second model; no person has assessed the result.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data (special_categories only), controller_processor_duties (accountability/security/retention principles only), and cross_border_and_adequacy (SCC/BCR mechanism only) each carry T3 (industry secondary-source) support drawn from a 2023 draft-law consultation summary and a 2026 IAPP directory update, plus one T1 anchor (Law No. 2010/012 of 2010) whose substantive text was not retrievable beyond its title. The remaining six modules (data_subject_rights, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance beyond biometric/genetic definitions, children_and_vulnerable_groups, and most of enforcement_and_redress) carry no T1/T2 support and are populated with narrative + absent_field_provenance only, per gap discipline. No official Cameroonian government gazette or National Authority website was reachable during this research pass; all findings trace to paywalled secondary aggregators (DataGuidance) and one IAPP directory update.

Unresolved questions (8):

  • What is the official law number, promulgation date, and Official Gazette citation of the Cameroon data protection statute reportedly adopted in H2 2024?
  • Is the National Authority for the Protection of Personal Data operationally established, staffed, and receiving controller filings/registrations as of August 2026?
  • Does ANTIC (Agence Nationale des Technologies de l'Information et de la Communication) retain any concurrent or transitional supervisory role over personal data alongside the new National Authority?
  • What are the enumerated lawful bases, consent standards, DPO appointment thresholds, ROPA requirements, breach-notification timelines, and retention-period specifics under the final enacted text?
  • Are there any adequacy decisions received or granted by Cameroon, and is there a data-localisation mandate?
  • What sector-specific overlays (financial, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) exist under Cameroonian law?
  • What are the regulator's maximum penalty powers and any recorded enforcement actions or fines to date?
  • Are there children/minors-specific provisions (parental consent age threshold, profiling bans) in the enacted law?

Escalate to primary-source review: yes