Jurisdiction Guides / Africa
Morocco Privacy & Data Protection Laws
Every regime below can apply to a business handling Morocco residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Modeled on the pre-GDPR French/European framework. It applies to processing carried out by a controller established in Morocco, and to a controller not established in Morocco that uses means of processing located in Moroccan territory other than for mere transit — an equipment-based test, so the trigger below is modeled on established presence only. The operative feature for any business with a Moroccan entity is the notification and authorization regime run by the Commission Nationale de controle de la protection des Donnees a caractere Personnel (CNDP): ordinary processing must be declared to the CNDP before it starts, and sensitive-data processing, interconnections, and transfers outside Morocco require prior authorization. Reform to align the law with GDPR-era concepts has been under discussion for several years without enactment — confirm the current position before assuming a modernized framework applies.
Cross-Border Data Transfer · 1
Art. 43 permits transferring personal data to a foreign state only where that state ensures a sufficient level of protection of privacy and of fundamental rights and freedoms, with the CNDP publishing and updating the list of countries it regards as adequate; Art. 44 supplies the exceptions where a transfer to a non-adequate destination is nonetheless permitted, notably the data subject's express consent. Where neither route is available, prior CNDP authorisation is required — and Morocco is one of the very few jurisdictions in this dataset where getting this wrong is a CRIMINAL matter rather than an administrative one: Art. 60 provides for imprisonment of three months to one year and a fine of MAD 20,000 to 200,000, or one of those penalties, for transferring personal data abroad in breach of Arts. 43-44. The CNDP has publicly announced enforcement over unnotified transfers. Marked 'check': the operative texts are French and Arabic originals, and reform to modernise the 2009 law has been under discussion for years without enactment.
Other Africa jurisdictions