Morocco

Substantial

Law No. 09-08 on the Protection of Personal Data

Authority: Commission Nationale de Contrôle de la Protection des Données (CNDP) | Enforcement: Active | Enacted: February 2009

Overview

Morocco enacted data protection legislation in 2009, inspired by the French model. The CNDP is an active regulator. Morocco was the first African country to join Convention 108. The framework covers prior authorisation, data subject rights, and cross-border transfers.

14-Topic Coverage

Data Protection Authority

Fully Addressed

CNDP independently oversees compliance, handles complaints, and issues authorisations.

Data Subject Rights

Fully Addressed

Rights to access, rectification, objection, and deletion.

Cross-Border Transfer

Fully Addressed

Transfers to adequate countries per CNDP list, or with CNDP authorisation.

Breach Notification

Partially Addressed

No explicit statutory breach notification. CNDP guidance recommends notification.

DPO Requirements

Partially Addressed

Data controller must register processing with CNDP. No formal DPO role.

Children's Data

Partially Addressed

General provisions apply. No specific age-based provisions.

Penalties & Enforcement

Fully Addressed

Fines from MAD 10,000 to MAD 300,000. Criminal penalties including imprisonment.

Sector-Specific Rules

Fully Addressed

BAM financial data rules, health data regulations, telecom provisions.

AI & Automated Decisions

Partially Addressed

Right to not be subject to automated decisions. National AI strategy published.

Data Localisation

Not Addressed

No general data localisation requirement.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Fully Addressed

Law applies to both public and private sector data processing.