Compliance · Law 09-08 · July 2026

What does Morocco’s Law 09-08 actually require of your business?

The direct answer: if you process any personal data in Morocco — customers, employees, prospects — you must file with the CNDP before you start, have a lawful basis, secure the data, and treat any foreign hosting as a regulated transfer.

Article

The short answer: Law 09-08 applies to virtually every Moroccan organization, because virtually every organization processes personal data — a customer file, a payroll, a recruitment inbox. It imposes four core duties: file with the CNDP before processing starts (a declaration for ordinary data, a prior authorization for sensitive data), process lawfully and inform the people concerned, secure the data with measures you can evidence, and treat any transfer outside Morocco — including foreign cloud hosting — as a separately regulated operation.

Who it covers

Any company, association, or public body that collects, stores, or uses data about identifiable people in Morocco falls under the law and the supervision of the CNDP, Morocco’s data protection authority. There is no small-business exemption for the core duties: a ten-person exporter with a client spreadsheet is a data controller just as a bank is.

The four duties, in practice

File first. The default formality is a prior declaration to the CNDP; processing involving sensitive data — health, biometrics, opinions, beliefs, offenses — requires prior authorization instead, and cannot lawfully begin without it. Operating without the right filing is not an administrative slip: the law provides criminal sanctions, with fines that practitioners cite up to 300,000 MAD and imprisonment for the most serious breaches.

Lawful basis and transparency. You need a valid ground for each processing purpose — consent, contract, legal obligation, legitimate interest — and the people concerned must be informed of what you collect and why.

Security you can prove. Access control, encryption, logging, incident procedures, staff awareness — documented, current, and producible if the CNDP comes asking.

Transfers are their own regime. Under Articles 43 and 44, personal data may leave Morocco only toward adequately protective destinations or with the CNDP’s authorization. Hosting your CRM or email on servers abroad is a transfer — even when the destination is an excellent European datacenter. This is the point most cloud projects miss.

Where to start

Map what personal data you hold and where it lives; identify which filings you owe; fix the gaps in security you cannot yet evidence. Our free Governance Readiness Assessment scores exactly these dimensions in minutes, in English, French, or Arabic. This article is general information, not legal advice — filings and legal qualification belong with qualified Moroccan counsel.

← All articles

Talk to us about this topic

Book a discovery call — in French, Arabic, or English — and we’ll map this to your organization.

Get FutureRoc in