Consumer protection in the sphere of banking products and services in Cameroon comprises the body of laws, regulations, and institutional rules established to guarantee fair treatment, transparency, and safety for individuals availing themselves of financial services. It serves to protect consumers against fraud, predatory lending, concealed charges, and unfair commercial practices, whilst ensuring the provision of clear and accurate information pertaining to risks and costs, and the availability of effective mechanisms for the resolution of complaints.
Key Aspects of Consumer Protection in Banking in Cameroon
- Transparency & Disclosure: Banks in Cameroon are required to provide clear and comprehensible information regarding the terms and conditions, interest rates, and fees applicable to their products and services, including by way of fee information documents or key facts statements, as appropriate.
- Fair Treatment & Suitability: Financial institutions in Cameroon are required to conduct themselves with honesty and professionalism in all dealings with consumers, ensuring that any products sold are appropriate and suitable for the individual needs of the consumer concerned.
- Data Security & Privacy: Consumer protection mechanisms include safeguards designed to ensure the confidentiality of customers' personal and financial information.
- Redress & Complaint Handling: Consumers have the right to access dispute resolution mechanisms that are efficient, affordable, and independent, ensuring they can seek and obtain fair compensation where appropriate.
- Responsible Lending & Anti-Usury: Applicable regulations in Cameroon prohibit unethical debt collection practices and impose an obligation on lenders to conduct a thorough assessment of a borrower's capacity to repay prior to extending credit, thereby affording protection against predatory lending practices.
- Protection of Funds: Measures such as deposit insurance protect consumer deposits.
OBLIGATION OF CONFIDENTIALITY, SECURITY AND PROTECTION OF PERSONAL DATA BY FINANCIAL INSTITUTIONS IN CAMEROON
The collection, recording, processing, storage, and sharing of consumers' personal data by regulated institutions must be carried out lawfully, fairly, and without fraud, in accordance with the provisions of Regulation No. 03/18/CEMAC/UMAC concerning the conditions for the operation, control, and supervision of the activities of credit information bureaus.
Regulated institutions are prohibited from collecting, storing, processing, or disseminating sensitive consumer data.
Regulated institutions must ensure the integrity and confidentiality of information covered by professional secrecy, particularly consumers' personal and financial information, using appropriate control and protection mechanisms.
Regulated institutions must, in particular, implement security measures for their premises, information systems, and databases to prevent files from being altered, damaged, or accessed by unauthorized third parties.
When personal data has been collected from the consumer, the regulated entity is required to:
- Inform the consumer of the purposes of the processing and the identity of the possible recipients of the personal data;
- Inform the consumer of their right to rectification and erasure.
The regulated entity is required to obtain the prior consent of each consumer before transmitting their personal data to third parties, with the exception of credit bureaus and any person against whom banking secrecy does not apply.
Consumers have the right to rectification when their personal data is found to be inaccurate or incomplete. They also have the right to erasure when:
- The personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- Consent was not given or the right to object was not exercised;
- The personal data have been unlawfully processed.
The right to rectification and erasure may be exercised by any means that leaves a written record. The data subject is required to respond to this request within fifteen days of receiving it.
It is prohibited for persons involved in the management, administration, control, or operation of regulated institutions to use a consumer's confidential information and personal data, which they become aware of in the course of their work, to carry out, directly or indirectly, transactions for their own benefit or to benefit other persons.
Regulated institutions must ensure the security of the payment instruments and means they make available and manage for consumers.
In the event of a fraudulent or unauthorized payment transaction, regardless of the location or platform from which it was ordered or executed, the payer's institution must reimburse the payer, within one month of becoming aware of the transaction or being notified of it, for the amount of this unauthorized payment transaction and, where applicable, restore the debited account within the same period to the state it would have been in had the unauthorized payment transaction not occurred.