Comprehensive Privacy Law
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Morocco · February 18, 2009 (implementing decree May 21, 2009)
Verify detailsModeled on the pre-GDPR French/European framework. It applies to processing carried out by a controller established in Morocco, and to a controller not established in Morocco that uses means of processing located in Moroccan territory other than for mere transit — an equipment-based test, so the trigger below is modeled on established presence only. The operative feature for any business with a Moroccan entity is the notification and authorization regime run by the Commission Nationale de controle de la protection des Donnees a caractere Personnel (CNDP): ordinary processing must be declared to the CNDP before it starts, and sensitive-data processing, interconnections, and transfers outside Morocco require prior authorization. Reform to align the law with GDPR-era concepts has been under discussion for several years without enactment — confirm the current position before assuming a modernized framework applies.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.