Policy brief

Laws before regulators: data protection in Central Africa and Cameroon’s missing authority

Central African states have adopted data protection laws faster than they have built the authorities to enforce them. Cameroon’s strict 2024 law shows the cost: duties that cannot yet be met, and rights that cannot yet be enforced.

Author
ACTPOL
Published
Topics
Data protection and privacy, Cybersecurity and cybercrime
Region
Central Africa
Region: Central Africa

Key points

  • Cameroon’s 2024 law requires prior authorisation for processing and for every transfer abroad, but the authority that must grant it had not been created when the compliance period ended on 23 June 2026.
  • Across the region, laws have come first and regulators late. Congo took more than five years to create its commission, and the DRC’s authority has not been set up.
  • Gabon shows what an operating authority can do, including challenging data sharing between state agencies.
  • Cameroon should create its authority now, with real independence, and Central African states should build a common framework for transfers.

The gap between law and enforcement

Central Africa is often left out of the continent’s data protection debate, but it offers one of its clearest lessons. Most states in the region now have data protection laws. Far fewer have authorities able to apply them. A law without a regulator gives people rights they cannot enforce, and gives organisations duties they cannot always meet.

Cameroon shows this most sharply. This brief examines its 2024 law, compares it with its neighbours, and sets out what governments in the region should do next.

Cameroon: a strict law awaiting its regulator

Law No. 2024/017 of 23 December 2024 relating to personal data protection in Cameroon is a comprehensive statute.1 It applies to processing by the State, local authorities and private persons, including the data of anyone “established, resident or in transit in Cameroon”. It gives people rights of access, rectification, erasure, objection, restriction and portability, and a right to object to decisions based solely on automated processing, including profiling.2

It is also unusually strict. Consent is the general rule: processing requires the data subject’s “prior, free, informed, specific and unambiguous consent”, with exceptions only for legal obligations, tasks in the public interest and the protection of health.3 Unlike most modern data protection laws, it offers no separate basis for performing a contract or pursuing legitimate interests. Any processing without prior authorisation is prohibited, and unauthorised processing can be fined between 5 and 50 million CFA francs.4 Every transfer of personal data abroad needs the prior authorisation of the Personal Data Protection Authority, and an unlawful transfer can be punished with three to ten years’ imprisonment. Companies face criminal fines of up to one billion CFA francs.5

Everything turns on that Authority. The law declares it an “independent public body”, but leaves its creation, organisation and functioning entirely to a decree of the President of the Republic.6 Organisations had 18 months from promulgation to comply, a period that ended on 23 June 2026.7 Yet as of July 2026, law firms advising on the law still described the Authority as “expected to be established by decree”, and we found no decree creating it.8

The result is a legal trap. Organisations are exposed to sanctions for lacking authorisations that no one can yet issue, and individuals have rights with no regulator to hear their complaints. Paradigm Initiative warned during the bill’s passage that, although the law provides for the Authority’s independence, the same provision gives the President “blanket powers to issue decrees”.9

A duty to obtain an authorisation that no one can grant is not regulation. It is uncertainty, and it falls hardest on those trying to comply.

The law also leaves the state’s most sensitive processing outside its general rules. Processing for security and defence, and processing relating to health, justice and civil status, is to be governed by specific texts.10 Meanwhile the 2010 cybersecurity law continues to require network operators and service providers to retain connection and traffic data for ten years, and the national cybersecurity agency, ANTIC, reported processing 32,500 judicial requisitions in 2025.11 The new law does not say how those regimes fit together.

The region: laws first, regulators later

Cameroon is not alone. Across the region, the gap between enactment and enforcement is the norm.

  • Republic of the Congo adopted its data protection law in 2019, but created its supervisory commission only in March 2025, by a separate law. We found no evidence that its members have been appointed.12
  • Democratic Republic of the Congo created a Data Protection Authority in its 2023 Digital Code. It has not been set up, and a ministerial order of August 2024 gave its functions to the telecommunications regulator in the meantime, an arrangement many legal scholars consider unlawful.13
  • Central African Republic adopted a data protection law in January 2024 and gave the digital economy ministry 12 months to establish a supervisory agency, carrying out its functions itself until then. In January 2026 it was unclear whether an authority had been appointed.14
  • Chad entrusted its 2015 law to ANSICE, a cybersecurity and electronic certification agency that a 2022 assessment found was not independently structured.15
  • Equatorial Guinea adopted a law in 2016 whose authority was reported as not yet operational in 2022.16

Gabon is the exception. Its 2023 law replaced the old commission with an independent administrative authority, the APDPVP, with power to impose fines of up to 100 million CFA francs, and more for repeat breaches.17 The authority is visibly at work. In December 2025 its president demanded the immediate suspension of a data-sharing operation between the national social security fund, the national health insurance fund and the national digital infrastructure agency, launched without referral to the authority.18 That is what an independent authority is for: asking the state to follow its own law.

A thin regional framework

Central Africa also lacks the regional rules that bind neighbours elsewhere. CEMAC has electronic communications directives from 2008 and banking rules on consumer data, but no general data protection instrument. ECCAS ministers adopted model laws on data protection in 2016, but they are not binding.19 ECCAS began work on a common framework for cross-border data governance at a regional workshop in Douala in August and September 2026.20

Continental law has not filled the gap. Of the states discussed here, only the Republic of the Congo and the DRC have ratified the African Union’s Malabo Convention. Cameroon and Chad have signed without ratifying, and the Central African Republic, Gabon and Equatorial Guinea have taken no action.21 The Central African Republic’s law already treats CEMAC and ECCAS as the reference zone for transfers, a sign of how a regional approach could work.22

Recommendations

  1. Create Cameroon’s Authority now, and make it independent in fact. The President should issue the decree without further delay. It should give members fixed terms, protect them from removal except for stated cause, and give the Authority its own budget.
  2. Suspend sanctions that depend on the missing Authority. Until the Authority can issue authorisations, the government should confirm publicly that organisations will not be penalised for lacking them, while the law’s other duties continue to apply.
  3. Modernise Cameroon’s legal bases and transfer rules. Parliament should add contract and legitimate interests as bases for processing, replace blanket prior authorisation with registration and impact assessments for high-risk processing, and allow standard safeguards to cover routine transfers.
  4. Reconcile the new law with the cybersecurity regime. The ten-year retention of traffic data and access to it by investigators should be brought within the new law, with judicial authorisation for access.
  5. Staff and fund the region’s authorities. The DRC should establish its Authority, Congo should appoint its commission, and the Central African Republic should create its agency, each with an independent budget.
  6. Build a regional transfer framework. CEMAC and ECCAS should agree mutual recognition of transfers among states with data protection laws, and states that have not done so should ratify the Malabo Convention.

Quotations from French-language texts are ACTPOL’s translations.

Notes

  1. Presidency of the Republic of Cameroon, Law No. 2024/017 of 23 December 2024 relating to personal data protection in Cameroon, certified copy. ↩

  2. Law No. 2024/017, articles 2 and 38 to 46. ↩

  3. Law No. 2024/017, article 9. ↩

  4. Law No. 2024/017, articles 49 and 55. ↩

  5. Law No. 2024/017, articles 32, 69 and 71. ↩

  6. Law No. 2024/017, article 53. ↩

  7. Law No. 2024/017, article 73. ↩

  8. Amadagana & Partners, “Doing Business in 2026: Cameroon”, Chambers Practice Guides, July 2026; DLA Piper, Data Protection Laws of the World: Cameroon, March 2026. ↩

  9. Paradigm Initiative, “Privacy or peril? Unpacking Cameroon’s new data protection bill”, 21 November 2024. ↩

  10. Law No. 2024/017, articles 4 and 72. ↩

  11. Law No. 2010/012 of 21 December 2010 on cybersecurity and cybercrime, articles 7 and 25; Digital Business Africa, report on ANTIC’s 2025 figures, 21 January 2026. ↩

  12. Republic of the Congo, Law No. 29-2019 of 10 October 2019, Official Gazette No. 45-2019; Law No. 5-2025 of 29 March 2025 creating the national commission for the protection of personal data. ↩

  13. Ordinance-Law No. 23/010 of 13 March 2023 on the Digital Code, articles 262 and 266, as reproduced by droitnumerique.cd; droitnumerique.cd on the ARPTIC order, August 2024; DLA Piper, Data Protection Laws of the World: DRC, February 2026. ↩

  14. Central African Republic, Law No. 24.001 on the protection of personal data, 25 January 2024, article 57; Data Protection Africa, Central African Republic, January 2026. ↩

  15. DLA Piper, Data Protection Laws of the World: Chad, March 2026; Data Protection Africa, Chad, May 2022. ↩

  16. Data Protection Africa, Equatorial Guinea, June 2022. ↩

  17. Gabon, Law No. 025/2023 of 12 July 2023, articles 7 and 204. ↩

  18. Gabonreview, report on the APDPVP’s intervention, 10 December 2025. ↩

  19. ARCEP Chad, list of CEMAC directives; UN Economic Commission for Africa, press release on the ECCAS model laws, 6 December 2016. ↩

  20. Journal des Nations, report on the ECCAS workshop in Douala, 8 September 2026. ↩

  21. African Union, status list of the Convention on Cyber Security and Personal Data Protection, 2 February 2026. ↩

  22. Central African Republic, Law No. 24.001, article 27. ↩