Cameroon’s New Privacy Law Is Past Its Grace Period
Cameroon’s Law No. 2024/017 created a comprehensive personal-data regime in December 2024. Its 18-month compliance period ended on 23 June 2026, so the useful question is no longer whether organisations should prepare, but whether their controls can now demonstrate compliance.
The law is a major change for organisations operating in Cameroon or processing data connected to the country. It establishes rules for collection, use, security, data-subject rights, processor relationships and international transfers. It also creates meaningful financial and civil exposure.
The transition period mattered because privacy programmes cannot be built from a policy template alone. Organisations need evidence about what they collect, why they use it, where it moves and who can access it. That evidence should now exist.
The law applies beyond a privacy notice
Law No. 2024/017 regulates controllers and processors and sets conditions for lawful processing. Consent is important, but the law also recognises other grounds in defined circumstances, including legal obligations, public-interest functions and protection of health.
A website notice is therefore only the visible edge of the programme. The organisation also needs an internal record connecting each processing activity to its purpose, legal basis, retention period, recipients and security measures.
Security has become a legal control
The law requires controllers and processors to protect personal data and creates duties around personal-data breaches. Security reporting and breach communication cannot be left to a general incident plan that never distinguishes personal data from other information.
Security teams should be able to identify affected data sets, estimate the people and records involved, preserve evidence, assess likely harm and provide the legal team with a documented incident timeline. Contracts must also ensure that processors escalate incidents quickly enough for the controller to act.
International transfers require a real map
The law restricts transfers of personal data to third countries and provides for prior authorisation in the circumstances it covers. The statute also attaches substantial fines to an unauthorised transfer.
That makes the transfer map operational, not theoretical. Cloud hosting, overseas support, centralised identity, fraud analytics, email security, backups and remote administration may all make Cameroonian personal data available outside the country. A contract register that lists only the primary application will miss much of the actual path.
The expired grace period changes the posture
Article 73 gave existing organisations 18 months from promulgation to conform. That period has passed. Delays in secondary rules or institutional buildout should not be treated as an implied extension of the statutory deadline.
The defensible posture is to comply with the law that exists, document any point that genuinely depends on future regulatory procedure and keep the programme capable of adapting when the authority publishes further instruments.
What organisations should do now
- Inventory processing connected to Cameroon, including processor and subprocessor activity.
- Record purposes, legal bases, data categories, retention and recipients.
- Review consent and age-assurance processes where consent is relied upon.
- Map international transfers and identify any required authorisation.
- Test the personal-data breach workflow with legal, security and communications teams.
- Keep a compliance evidence pack ready for regulatory or contractual scrutiny.
The bigger change is accountability
Cameroon’s law follows many familiar privacy principles, but familiarity can create false confidence. A copied GDPR control set is not the same as a Cameroonian compliance record. Local transfer rules, authorisation requirements, enforcement provisions and regulator procedures need to be tracked as local obligations.
Official sources
- Presidency of Cameroon: Law No. 2024/017 of 23 December 2024
- Official English text of Law No. 2024/017
This article provides general information and is not legal advice.
Continue the series: Africa Cyber & Digital Law Series index


