WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Africa

Morocco Privacy & Data Protection Laws

Every regime below can apply to a business handling Morocco residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

February 18, 2009 (implementing decree May 21, 2009)
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Morocco Law 09-08
Verify details

Modeled on the pre-GDPR French/European framework. It applies to processing carried out by a controller established in Morocco, and to a controller not established in Morocco that uses means of processing located in Moroccan territory other than for mere transit — an equipment-based test, so the trigger below is modeled on established presence only. The operative feature for any business with a Moroccan entity is the notification and authorization regime run by the Commission Nationale de controle de la protection des Donnees a caractere Personnel (CNDP): ordinary processing must be declared to the CNDP before it starts, and sensitive-data processing, interconnections, and transfers outside Morocco require prior authorization. Reform to align the law with GDPR-era concepts has been under discussion for several years without enactment — confirm the current position before assuming a modernized framework applies.

Law No. 09-08 (promulgated by Dahir No. 1-09-15 of February 18, 2009); Decree No. 2-09-165Read regulation →

Cross-Border Data Transfer · 1

February 18, 2009 (implementing decree May 21, 2009)
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data — transfer of data abroad
Morocco Law 09-08 Arts. 43-44
Verify details

Art. 43 permits transferring personal data to a foreign state only where that state ensures a sufficient level of protection of privacy and of fundamental rights and freedoms, with the CNDP publishing and updating the list of countries it regards as adequate; Art. 44 supplies the exceptions where a transfer to a non-adequate destination is nonetheless permitted, notably the data subject's express consent. Where neither route is available, prior CNDP authorisation is required — and Morocco is one of the very few jurisdictions in this dataset where getting this wrong is a CRIMINAL matter rather than an administrative one: Art. 60 provides for imprisonment of three months to one year and a fine of MAD 20,000 to 200,000, or one of those penalties, for transferring personal data abroad in breach of Arts. 43-44. The CNDP has publicly announced enforcement over unnotified transfers. Marked 'check': the operative texts are French and Arabic originals, and reform to modernise the 2009 law has been under discussion for years without enactment.

Law No. 09-08, Arts. 43-44 (transfer) and Art. 60 (penalties)Read regulation →

Other Africa jurisdictions