BANKING AND FINANCE LAW IN CAMEROON

Credit information bureaus (CIBs) are new players in the CEMAC banking system, alongside credit institutions, microfinance institutions, and payment institutions. Their regulatory framework stems from Regulation 03/2018 CEMAC/UMAC of December 21, 2018, concerning the conditions for the operation, control, and supervision of the activities of credit information bureaus in the CEMAC region, supplemented by approximately fifteen instructions from the Governor of the BEAC signed in February 2020.

Credit bureaus are legal entities whose primary and exclusive activity is the collection, compilation, storage, and processing of data and information on the creditworthiness of individuals or legal entities from suppliers, with the aim of making this information available to users for a fee. They may also provide related services such as scoring, which uses statistics to assess, for example, a client's creditworthiness.

Credit information providers are primarily credit institutions, microfinance institutions, payment institutions, regional financing institutions such as the BDEAC (Development Bank of Central African States), regional or international credit guarantee institutions, insurance companies, debt collection agencies, fixed and mobile telephone operators, and water and electricity utility companies. Users of this information are almost the same entities, namely credit institutions, microfinance institutions, payment institutions, insurance companies, regional financing or credit guarantee institutions, debt collection agencies, and so on. The principle is reciprocity, as only information providers, with a few exceptions, can access the information stored in the database. The provision and collection of information from a Credit Information Bureau (CIB) is based on a contract previously signed between the provider or user and the CIB.

The information in question is essentially information about the creditworthiness of an individual or legal entity. This includes personal data, financial commitments (loan volume, maturity, terms and conditions, repayments, guarantees) or service obligations, borrowing or repayment capacity, credit history, etc. This information allows for the determination, at any time, of the client's financial situation, exposure to financial risks, and creditworthiness.

Credit Information Bureaus in Cameroon must be established as public limited companies with a board of directors and a minimum share capital of 500,000,000 million FCFA in cash. They must be licensed by the BEAC, which also regulates and supervises them. In this capacity, the BEAC can adopt applicable regulations, conduct on-site and documentary audits, and impose disciplinary or financial sanctions, as well as withdraw the license of these institutions.

In the course of their business, credit bureaus are subject to various obligations to ensure the security, reliability, and accessibility of the data they collect. For example, they must establish data protection units. They also have specific obligations towards the clients whose data they collect and process. A complaints handling procedure has also been implemented. Users, for their part, are required to obtain clients' prior consent before accessing any of their credit information.

While the objective of implementing Credit Information Centers (CICs) is commendable, as they can contribute to better analysis, assessment, and management of credit risks, thereby reducing or anticipating financial difficulties for businesses and individuals, the main risk lies in the protection of the data that will be collected, processed, and stored. While the risk of non-performing loans poses a threat to economies, the risk of cyberattacks against customer data collected by banking institutions is even more serious. Indeed, the issue is sometimes no longer solely financial and economic, but simply a matter of security.