The legal framework
Data protection rests on Law No. 2010/012 on cybersecurity and cybercrime (loi relative à la cybersécurité et à la cybercriminalité), applied by the Agence nationale des technologies de l'information et de la communication (ANTIC, national agency for information and communication technologies). A general data protection law of the kind several neighbouring countries have adopted has long been announced; before starting a procedure, check on the government's website or with the ANTIC whether such a law is now in force and which authority applies it. The texts take up the principles of the European model: a specific purpose (finalité), proportionality (proportionnalité), data security and the rights of access (droit d'accès) and rectification. The rights recognised are information, access, rectification and objection (opposition); erasure (effacement) is provided for by the most recent texts. Processing must be declared (déclaration) or authorised in advance (autorisation préalable), depending on its nature, and transfers abroad are regulated and often subject to the authority's authorisation. Abuses involving advertising text messages, telecommunications and mobile money also fall to the telecommunications regulator. Loan apps that use access to the phone's contacts to put pressure on borrowers are a practice targeted by the authorities of the region. The regional framework is the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention). As throughout the region, the difficulty lies in effectiveness: the authorities often lack resources, and companies' awareness remains low. The authorities systematically ask for evidence: screenshots, dates and copies of letters.
British and Irish nationals living in Cameroon, and British-Cameroonian couples, deal with two systems depending on who holds their data. Against Cameroonian bodies — mobile operators, mobile money services, banks, employers, loan apps — Cameroonian law applies, with the ANTIC as the point of contact and, for abuses by text message or mobile money, the telecommunications regulator. Against organisations established in the UK — a British bank, the NHS, HMRC, an employer, online services — the UK GDPR and the Data Protection Act 2018 continue to apply whatever your country of residence, as does the GDPR for organisations in Ireland and the rest of the EU, and both also apply to services outside the UK or the EU that target people there: the reply to an access request is due within one month and is normally free, and a complaint to the ICO (the Information Commissioner's Office) or to Ireland's Data Protection Commission costs nothing. That route is often the faster one. For British companies, charities, churches and universities with partners in Cameroon, the consequence runs the other way: Cameroon is covered neither by UK adequacy regulations nor by an EU adequacy decision, so transfers of personal data from the UK need appropriate safeguards — usually the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses — and transfers from Ireland the standard contractual clauses (article 46 of the GDPR); Cameroonian law may in turn make transfers abroad subject to authorisation.
The second point concerns what is on the phone. In Cameroonian prosecutions under article 347-1 of the Code pénal (Penal Code), which punishes same-sex relations, messages and photos have been the main source of evidence and have served as the basis for convictions; for anyone with such content on a phone, digital caution — screen lock, encryption, nothing passed on through third parties — is a safety measure. The FCDO's travel advice for Cameroon likewise notes that same-sex sexual acts are illegal there and that same-sex partners have been arrested and prosecuted. Intimate images shared against the will of the person shown are also a tool of blackmail (sextortion): never pay, keep the evidence and report it — in Cameroon to the police or the gendarmerie, with a report to the ANTIC; in the UK to the police, since sharing an intimate image without consent is an offence throughout the UK (in England and Wales under the Sexual Offences Act 2003 as amended by the Online Safety Act 2023), and in Ireland under Coco's Law of 2020. The Revenge Porn Helpline helps adults in the UK to have images removed from platforms. Cameroonians who live or study in the UK have all the rights of the UK GDPR towards UK organisations, whatever their nationality. And families in the UK who send mobile money to relatives in Cameroon, or set up a phone for them, help most with simple rules: never pass on a code, never let a loan app access the contacts, keep confirmation messages and screenshots.
Key points
| Law | Law No. 2010/012 on cybersecurity and cybercrime |
|---|---|
| Authority | ANTIC (Agence nationale des technologies de l'information et de la communication) |
| General data protection law | Long announced; check the current position before any procedure |
| Rights | Information, access, rectification, objection; erasure in the most recent texts |
| Formalities | Declaration or prior authorisation of processing, depending on its nature |
| Transfers abroad | Regulated, often subject to authorisation |
| Regional framework | African Union Malabo Convention |
| Advertising texts and mobile money | Abuses also handled by the telecommunications regulator |
| Loan apps | Pressure through the phone's contacts: a practice targeted by the region's authorities |
| Evidence | Keep screenshots, dates and copies of letters: the authorities ask for them systematically |
| British and Irish nationals | UK GDPR or GDPR against UK and EU organisations wherever you live (ICO, Data Protection Commission); no UK or EU adequacy decision for Cameroon; sharing intimate images without consent an offence in the UK and Ireland |
In practice
- Send a written access request to the organisation holding your data, citing the Cameroonian law and enclosing a copy of an identity document; keep the date and a copy of the letter.
- If it refuses or does not reply, refer the matter to the ANTIC, usually by letter or form; for text messages or mobile money, also to the telecommunications regulator.
- For a service established or represented in the UK or the EU, rely on the UK GDPR or the GDPR at the same time — often the faster route — and, without a reply within a month, complain to the ICO or to the Data Protection Commission.
- Give loan apps no access to contacts, photos or location; if an app puts pressure on you through your contacts, keep screenshots and inform the authorities.
- Before travelling to Cameroon, check your phone: screen lock, encryption, backups; do not pass sensitive content on through third parties.
- If an intimate image is shared or used for blackmail: do not pay, keep the evidence, ask the platform to remove it and report it — in Cameroon to the police or the gendarmerie, in the UK to the police, with the Revenge Porn Helpline's help for removal.
- British organisations that send personal data to Cameroon put the International Data Transfer Agreement or the UK Addendum in place and check whether Cameroonian law requires a declaration or an authorisation.
Cost and coverage
Procedures before the Cameroonian authorities are free; costs arise at most for copies, translations and, in court proceedings, a lawyer. In the UK, an access request is normally free and a complaint to the ICO costs nothing, including for people who live abroad; the same applies to the Data Protection Commission in Ireland. Compensation for a breach of the UK GDPR is claimed in the civil courts, with a lawyer and a risk of costs.
Recent changes
The common challenge across the region is effectiveness: the authorities often lack resources and companies' awareness remains low, although the growth of mobile money and digital services is speeding up checks. In the UK, the Data (Use and Access) Act 2025 amended data protection law, with changes coming into force in stages, and the Online Safety Act 2023 broadened the offence of sharing intimate images without consent in England and Wales from January 2024.
Where to go
- ANTIC: application of Law No. 2010/012, reports and warnings.
- Telecommunications regulator: abuses involving text messages, telecommunications and mobile money.
- Consumer associations and cliniques juridiques (law clinics): support.
- Police and gendarmerie: complaints of blackmail or of images being shared.
- In the UK: the ICO (ico.org.uk), the police and the Revenge Porn Helpline; in Ireland: the Data Protection Commission and An Garda Síochána; British High Commission in Yaoundé if you are arrested in Cameroon; Irish citizens abroad: Department of Foreign Affairs.
Worth knowing
Your rights do not stop at the border: an online service established in the UK or Europe, or one that targets people there, must respect the UK GDPR or the GDPR wherever you live — so you can approach both the Cameroonian authority and the competent UK or European regulator. In Cameroon itself, enforcement resources are limited: the best protection is caution about what is on your phone and what an app is allowed to access.
Frequently asked questions
Does the UK GDPR still protect me if I live in Cameroon?
Against organisations established in the UK — your British bank, HMRC, the NHS, online services — yes, whatever your country of residence, and also against services outside the UK that target people in the UK: a reply to an access request within one month, normally free, and a free complaint to the ICO. Organisations in Ireland and the rest of the EU are bound by the GDPR in the same way. Against Cameroonian bodies, Law No. 2010/012 applies, with the rights of information, access, rectification and objection, enforced through the ANTIC; for text messages and mobile money, the telecommunications regulator is also competent.
A loan app is putting pressure on me through my contacts — what can I do?
Keep screenshots of the messages sent to you and to your contacts, withdraw the app's access to contacts, photos and location in the phone's settings, and inform the ANTIC and the telecommunications regulator: the practice is known to the authorities of the region, which are acting against it. If there are threats, make a complaint to the police or the gendarmerie. Warn your contacts through another channel so that they do not respond to the messages. For the next loan: no app that asks for your address book.
Can my UK employer send my data to its office in Douala?
Yes, but not without safeguards: Cameroon is covered neither by UK adequacy regulations nor by an EU adequacy decision, so the transfer needs appropriate safeguards — from the UK usually the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses — and your employer must tell you about the transfer. Cameroonian law may in turn make transfers abroad subject to authorisation. If in doubt, ask the company's data protection officer; complaints go to the ICO, or to the Data Protection Commission for an employer established in Ireland.
Official sources and links
- Services du Premier ministre — official government website — laws and regulations of Cameroon, including Law No. 2010/012 on cybersecurity and cybercrime (French version)
- ANTIC — national ICT agency: application of Law No. 2010/012, warnings and advice
- ICO — make a complaint — UK regulator
