Country:摩洛哥 · Data Privacy
Morocco · Data Privacy
Moroccan personal data protection centers on the 2009 Personal Data Protection Law (Law 09-08), supervised by the independent CNDP (Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel). The legislative model is the former EU Directive 95/46/EC; principles are similar to the GDPR but retain a 'prior declaration/prior authorization' system. It applies to controllers processing personal data in Morocco and foreign entities outside Morocco that use processing means within Morocco (including servers, cookies, subcontractors) — so Chinese subsidiaries, representative offices, and digital platforms using local servers are all covered. All personal data processing must be declared to the CNDP before processing (standard low-risk = declaration déclaration; sensitive data/interconnection/cross-border transfer to insufficiently protected countries require prior authorization autorisation). Violations can incur fines of MAD 10,000–600,000, 3 months–4 years imprisonment, doubled for legal persons, and possible business suspension.
Key points
- Jurisdiction trigger: controller established in Morocco, or outside Morocco using processing means in Morocco (servers, cookies, subcontractors, partners) — Chinese entities in Morocco and those using local cloud/SaaS fall within.
- Pre-processing obligations: standard processing requires a prior declaration (déclaration) to the CNDP; sensitive data (health, biometrics, political opinions, unions, criminal records), file interconnection, and cross-border transfers to insufficiently protected countries require prior authorization (autorisation).
- Cross-border transfers: Articles 43–44 require CNDP prior authorization for transfers to countries without adequate protection; unless exceptions apply (data subject explicit consent, necessary for contract performance, public interest, legal protection, public registers), standard contractual clauses (SCC) or binding corporate rules (BCR) must provide safeguards; violations can incur 1 year imprisonment + MAD 200,000 fine.
- Foreign company representative: entities without an establishment in Morocco but covered by the law must appoint a representative in Morocco as the CNDP contact point.
- Data subject rights: information, access (copy generally within 10 days), rectification/blocking, objection; controllers must have a lawful basis (consent/contract/legal obligation/material interest/public interest/legitimate interest).
- Differences from the GDPR: no data portability right, no mandatory 72-hour breach notification, no 4%-of-global-turnover fines; instead retains the prior declaration/authorization system with criminal penalties.
Procedure
- Map data processing activities (employees, customers, suppliers, visitors, etc.) and determine risk levels.
- Submit a prior declaration (déclaration) to the CNDP for low-risk standard processing; submit a prior authorization (autorisation) for high-risk/sensitive/cross-border processing.
- Develop privacy notices, consent mechanisms, and data subject rights response processes.
- Appoint and register a Moroccan representative for foreign companies.
- Cross-border transfers: sign SCCs or group BCRs and apply for CNDP authorization (if the destination lacks adequate protection).
- Establish technical and organizational security measures, retain records, and review periodically.
Hard requirements
- Declare to the CNDP before processing (declaration or authorization)
- Sensitive data/interconnection/cross-border transfers require prior authorization
- A lawful processing basis and data subject rights guarantees
- Foreign companies must appoint a Moroccan representative
- Cross-border transfers require adequate protection or SCC/BCR + CNDP authorization
Costs
CNDP filing fees (per official rates); lawyer/DPO service fees separateViolation fines MAD 10,000–600,000; serious cases 3 months–4 years imprisonment; legal persons doubled⏱ ⏱ Timeline:Authorization review generally about 2 months; filings must be completed before processing begins.⚠ Common risks
- Processing personal data without filing: criminal and administrative penalties
- Cross-border transfer without CNDP authorization (including overseas cloud/SaaS): 1 year imprisonment + MAD 200,000 fine
- Foreign companies without a Moroccan representative: missing contact, compliance gaps
- Missing data subject rights responses: complaints and penalties
- Assuming only EU GDPR applies while ignoring the extraterritorial effect of Law 09-08
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese entities processing personal data in Morocco (subsidiaries, representative offices, platforms using local servers), and group scenarios transferring Moroccan employee/customer data back to China or third countries.
Prerequisites
- In-Morocco data processing activities and data subject categories identified (employees, customers, suppliers)
- Knowledge of the extraterritorial effect of Law 09-08 (overseas entities using Moroccan means are covered)
- CNDP filing route (declaration/authorization) planned
- Cross-border transfers require SCC/BCR and authorization applications
- Foreign companies must appoint a Moroccan representative
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Data processing mapping. Inventory all in-Morocco personal data processing (recruitment, HR, customer CRM, suppliers, visitors, monitoring); determine whether sensitive data, interconnection, or cross-border transfers are involved; assess risk levels and filing types. | In-Morocco legal/compliance + China data protection team | 1–2 weeks | Internal cost | Record of processing activities (RoPA) | Group HR data returned to HQ and overseas cloud use both count as transfers. Penalty:Missed sensitive/cross-border cases lead to unauthorized processing and criminal penalties. |
| 2 | CNDP filing (declaration or authorization). Standard low-risk processing submits a prior declaration (déclaration) to the CNDP; sensitive data, interconnection, and cross-border transfers to insufficiently protected countries submit a prior authorization (autorisation) with safeguards. Authorization review about 2 months; silence is deemed refusal. | In-Morocco compliance + CNDP | Declaration weeks; authorization about 2 months | CNDP fees; advisor fees | CNDP declaration/authorization application | Filing must be completed before processing begins. Penalty:Processing without filing: fines MAD 10,000–600,000; criminal liability in serious cases. |
| 3 | Appoint a Moroccan representative. Foreign companies without an establishment in Morocco but covered by the law must appoint a natural or legal person as the Moroccan representative, serving as the CNDP and data subject contact point, identified in the filing. | Chinese parent + local representative | 1 week | Representative service fees | Representative appointment; CNDP registration | Commonly a local subsidiary, accounting firm, or law firm. Penalty:No representative means missing contact, compliance gaps, and penalties. |
| 4 | Privacy notices and consent mechanisms. Establish transparent notices (purpose, basis, recipients, retention) and valid consent mechanisms (explicit consent for sensitive data); implement access (within 10 days), rectification, blocking, and objection rights responses. | In-Morocco compliance + IT | 2–4 weeks | Internal cost | Privacy policy; consent records; rights response SOP | Consent must be provable and revocable. Penalty:Missing rights responses trigger complaints and penalties. |
| 5 | Cross-border transfer compliance (SCC/BCR + authorization). Before transferring Moroccan data to China/third countries: assess destination adequacy (EU generally deemed adequate); non-adequate destinations require SCC or group BCR safeguards and CNDP prior authorization. Overseas cloud/SaaS also constitutes a transfer requiring SCC and filing. | In-Morocco compliance + China data team + CNDP | Authorization about 2 months | Legal document drafting; CNDP fees | SCC/BCR; CNDP cross-border authorization | China is generally not listed as adequately protected; authorization is required. Penalty:Unauthorized cross-border transfer: 1 year imprisonment + MAD 200,000 fine; controller fully liable. |
| 6 | Security and ongoing review. Implement technical and organizational security measures (access control, encryption, retention minimization), retain processing records, periodically review filings and measures, and update authorizations promptly. | In-Morocco IT/compliance | Ongoing | Operations cost | Security baseline and records; annual review | Business/system changes require synchronized filing updates. Penalty:Missing measures aggravate breach penalties. |
✅ Self-check list
⚠ Common pitfalls
Assuming only GDPR applies影响:Ignoring the extraterritorial effect of Law 09-08 and the prior-filing system; criminal penalties.规避:Benchmark Law 09-08; CNDP filing is a hard prerequisite.
Cross-border transfer without CNDP authorization影响:1 year imprisonment + MAD 200,000 fine; controller fully liable.规避:Sign SCC/BCR and obtain CNDP authorization before transferring to non-adequate countries such as China.
No Moroccan representative appointed影响:Missing contact, compliance gaps, and penalties.规避:Foreign companies without an establishment appoint a local representative and list it in filings.
Sensitive data without prior authorization影响:Unauthorized processing triggers criminal liability.规避:Apply separately for authorization for health/biometric/union etc. sensitive processing.
Overseas cloud/SaaS not reported as a transfer影响:Constitutes unauthorized cross-border transfer.规避:Include all overseas-hosted SaaS/cloud in transfer filings with SCC.
📅 Ongoing post-incorporation obligations
- Keep CNDP declarations/authorizations valid and updated with business changes
- Respond to data subject rights requests promptly
- Renew cross-border transfer authorizations on expiry
- Periodically review security measures and processing records
- Update representative information registrations on changes
🔗 Official portals
📎 Source:Moroccan Personal Data Protection Law Law 09-08 (promulgated 2009-02-18, implementing decree 2-09-165, fully effective 2011-03-16); National Personal Data Protection Control Commission (CNDP); DPO Consulting / Korte Law / Upsilon Consulting Morocco data compliance guides
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.