Concept mockup. Proposed by De Bouana Cameroon SARL for BGFIBank Cameroun, following digital audit DBC-AUD-BGFI-2026-01.

Read the proposal note
Data protection

Privacy policy

The data we process, why, for how long, and how to exercise your rights with our Data Protection Officer.

Version 1.0 In force since Last updated Previous versions archived and available on request

Demonstration document. This text illustrates the structure and level of detail expected. It is not legal advice and must be drafted, checked and approved by BGFIBank Cameroun's legal counsel and Data Protection Officer before any publication.

1. Data controller

The controller of personal data collected in the course of the banking relationship and the use of this website is:

BGFIBank Cameroun SA, avenue du General de Gaulle, angle rue Carras, Bonanjo, Douala, Cameroon.

Processing is carried out in accordance with Law No. 2024/017 of 23 December 2024 on the protection of personal data in Cameroon, which entered into full application on 23 June 2026.

2. Data Protection Officer

In accordance with Law No. 2024/017, BGFIBank Cameroun has appointed a Data Protection Officer. They are your single point of contact for any question or request concerning your personal data, and the bank's point of contact with the supervisory authority.

How to reach them
By email: dpo@bgfibank.cm
By post: Data Protection Officer, BGFIBank Cameroun SA, avenue du General de Gaulle, angle rue Carras, Bonanjo, Douala, Cameroon
Through the online form: Complaints page, selecting the personal data request category

Every request addressed to the Officer is recorded, time stamped and tracked. You receive an acknowledgement, then a reasoned response within the period stated in section 7.

3. Data we process

Depending on your situation and the services you use, we process in particular:

  • Identification data: surname, given names, date and place of birth, nationality, parentage, identity document number and dates.
  • Contact data: postal address, email address, telephone numbers.
  • Professional and financial data: occupation, employer, income and assets, to the extent needed to assess an application.
  • Banking and transaction data: account numbers, operations, payment instruments, outstanding balances.
  • Connection data: technical identifiers, connection logs for online services, IP address, device type.
  • Biometric data, where applicable, for customer due diligence purposes and only with your explicit consent.

We collect only the data necessary for the purposes described below. Mandatory fields are indicated at the point of collection.

4. Purposes and legal bases

Processing purposes and corresponding legal bases
PurposeLegal basis
Opening, managing and closing accountsPerformance of the contract
Executing payment and transfer operationsPerformance of the contract
Customer due diligence, anti money laundering and counter terrorist financingLegal obligation
Credit risk assessmentPerformance of the contract and legitimate interest
Systems security and fraud preventionLegitimate interest
Handling complaints and requestsLegal obligation and performance of the contract
Marketing and offer personalisationConsent
Non essential website audience measurementConsent

Where processing rests on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before that withdrawal.

5. Recipients

Your data is intended for authorised staff of BGFIBank Cameroun. It may be shared, only so far as necessary:

  • with entities of Groupe BGFIBank, for consolidated risk management and compliance;
  • with technical providers acting on the bank's instructions, bound by a processing agreement and by confidentiality obligations;
  • with payment and clearing systems, in particular GIMAC, to execute your operations;
  • with judicial, tax and supervisory authorities, including COBAC, upon lawful request or under a legal obligation.

Where a transfer outside Cameroon is necessary, it takes place only with appropriate safeguards and in accordance with Law No. 2024/017.

6. Retention periods

  • Contractual relationship dataDuration of the relationship, then 10 years
  • Customer due diligence records10 years after the relationship ends
  • Online service connection logs12 months
  • Complaint files5 years after closure
  • Marketing data3 years after the last contact
  • Consent recordsDuration of processing, then 5 years

These periods are indicative in this demonstration document and must be settled in the bank's processing register.

7. Your rights and how to exercise them

You hold the following rights over data concerning you:

  • Right of access: obtain confirmation that data concerning you is processed, and receive a copy.
  • Right to rectification: have inaccurate data corrected or incomplete data completed.
  • Right to erasure: request deletion of your data, subject to the statutory retention obligations that apply to a credit institution.
  • Right to object: object to processing based on legitimate interest, and at any time to marketing.
  • Right to restriction: request the temporary freezing of contested processing.
  • Right to portability: receive, in a structured format, the data you provided to us.
  • Post mortem directives: determine what happens to your data after your death.

How to exercise these rights. Send your request to the Data Protection Officer by one of the means given in section 2. State the right you wish to exercise and enclose a copy of a valid identity document.

  • AcknowledgementWithin 48 working hours
  • Reasoned responseWithin 30 days
  • Extension, complex requestA further 30 days, with prior notice
  • CostFree of charge

8. Data security

BGFIBank Cameroun implements technical and organisational measures designed to protect your data against loss, alteration, disclosure and unauthorised access: encryption of exchanges, access segregation on a least privilege basis, logging, backups and regular controls.

A data breach notification procedure is in place. Where a breach is likely to result in a high risk to your rights, you will be informed as soon as possible.

Security reminder. The bank will never ask you for your secret code, your password or a validation code received by SMS.

9. Cookies and trackers

This site uses cookies strictly necessary to its operation, which do not require your consent. Audience measurement and personalisation cookies are set only after your explicit agreement, collected by category.

Your choice is recorded with a time stamp, the scope of the purposes accepted and the version of this policy accepted. It is retained so that it can be produced to the supervisory authority. You may change or withdraw it at any time.

10. Mobile applications

The privacy declarations published on the application stores correspond to a single, verified statement of what the MyBGFIBANK CM application collects, processes and shares. Both stores present the same information.

This policy, hosted on the bgfibank.cm domain, is the reference document for the mobile application. No legal document of the bank is hosted on a third party consumer service.

Deletion of your data may be requested from within the application, or directly from the Data Protection Officer, within the limits of the statutory retention obligations applicable to a credit institution.

11. Complaint to the authority

If, after contacting us, you consider that your rights have not been respected, you may lodge a complaint with the Cameroonian authority competent for personal data protection, established by Law No. 2024/017 of 23 December 2024.

This route is independent of the banking complaints procedure described on the Complaints page, which falls under COBAC Regulation No. 01/20/CEMAC/UMAC/COBAC.