WorldPrivacyAtlas
Laws by country

Comprehensive Privacy Law

Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data

Morocco Law 09-08

Morocco · February 18, 2009 (implementing decree May 21, 2009)

Verify details

Modeled on the pre-GDPR French/European framework. It applies to processing carried out by a controller established in Morocco, and to a controller not established in Morocco that uses means of processing located in Moroccan territory other than for mere transit — an equipment-based test, so the trigger below is modeled on established presence only. The operative feature for any business with a Moroccan entity is the notification and authorization regime run by the Commission Nationale de controle de la protection des Donnees a caractere Personnel (CNDP): ordinary processing must be declared to the CNDP before it starts, and sensitive-data processing, interconnections, and transfers outside Morocco require prior authorization. Reform to align the law with GDPR-era concepts has been under discussion for several years without enactment — confirm the current position before assuming a modernized framework applies.

Law No. 09-08 (promulgated by Dahir No. 1-09-15 of February 18, 2009); Decree No. 2-09-165Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.