Cross-Border Data Transfer
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data — transfer of data abroad
Morocco · February 18, 2009 (implementing decree May 21, 2009)
Verify detailsArt. 43 permits transferring personal data to a foreign state only where that state ensures a sufficient level of protection of privacy and of fundamental rights and freedoms, with the CNDP publishing and updating the list of countries it regards as adequate; Art. 44 supplies the exceptions where a transfer to a non-adequate destination is nonetheless permitted, notably the data subject's express consent. Where neither route is available, prior CNDP authorisation is required — and Morocco is one of the very few jurisdictions in this dataset where getting this wrong is a CRIMINAL matter rather than an administrative one: Art. 60 provides for imprisonment of three months to one year and a fine of MAD 20,000 to 200,000, or one of those penalties, for transferring personal data abroad in breach of Arts. 43-44. The CNDP has publicly announced enforcement over unnotified transfers. Marked 'check': the operative texts are French and Arabic originals, and reform to modernise the 2009 law has been under discussion for years without enactment.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.