Autorité de Protection des Données Personnelles et de la Vie Privée (APDPVP, ex-CNPDCP), established 2012
1
published decisions tracked
APDPVP: 1
2025-02
latest decision
data updated 22 July 2026
The law
Law No. 001/2011 on the Protection of Personal Data, as amended by Law No. 025/2023 IN FORCE
commenced base law promulgated 2011-09-25 (JO 24-31 Oct 2011); amendment promulgated 2023-07-12 (JO 15 July 2023) · Official full text ↗
Scope
Any information relating to an identified or identifiable natural person (art. 6), aligned with the Malabo Convention definitions; applies to public and private controllers and processors.
Key obligations
Prior notification to the APDPVP for ordinary processing; prior authorisation for offence data, genetic data, exclusion-effect processing, interconnection, national ID numbers, social-difficulty data and identity-control biometrics: with a two-month decision window, renewable once, silence deemed rejection (art. 85); Simplified notification for low-risk processing categories identified by the APDPVP (art. 80); exemptions incl. public registers, associations, and DPO-appointing controllers except for cross-border transfers (art. 89); Mandatory DPO in GDPR-style cases (art. 125) with qualification and independence requirements (arts. 130, 138); Breach notification without delay (art. 142) and high-risk communication to data subjects (arts. 145-147)
DPO required
Yes, in defined cases: public authorities/bodies (except courts acting judicially), large-scale regular and systematic monitoring, or large-scale processing of sensitive and conviction data (art. 125); the DPO must hold professional DP-law qualifications (art. 130) and monitors compliance and DPIAs (art. 138).
Registration
Yes: notification or authorisation with the APDPVP depending on category; ministerial approval (after APDPVP opinion) for state-security and criminal-justice processing; DPO appointment exempts notification except for cross-border transfers.
Cross-border transfers
The 2023 amendment rewrote the transfer regime: transfers to another State ONLY on APDPVP authorisation, with the APDPVP guaranteeing destination sufficiency and publishing the adequacy list (art. 171); non-adequate destinations require the art. 173 CONJUNCTIVE derogation (express consent AND a necessity ground) or an APDPVP decision/decree on sufficient guarantees such as contractual clauses or internal rules; the APDPVP can ban, suspend or cancel transfers (art. 174). (Verified from the archived JO texts of both laws 2026-07-11, S27.)
Breach notification
Notify the APDPVP without delay, describing the breach, affected categories and numbers, remedial measures and DPO contact (art. 142); high-risk breaches communicated individually to data subjects in clear terms (arts. 145-146), with public-announcement fallback where individual notice is disproportionate (art. 147).
Penalties
Sanctions of XAF 1,000,000 to 100,000,000, rising to XAF 300,000,000 for recidivism (per the regulator's published scale); no notable enforcement decision identified as of end-2023: declaration regime active but sanction practice unpublished.
Authority
Autorité de Protection des Données Personnelles et de la Vie Privée (APDPVP, ex-CNPDCP)
Verified 2026-07-10
The regulator
Authority
Autorité de Protection des Données Personnelles et de la Vie Privée (APDPVP, ex-CNPDCP)