Country:摩洛哥 · Data Privacy
High confidenceUpdated 2026-08-03Handbook

Morocco · Data Privacy

Moroccan personal data protection centers on the 2009 Personal Data Protection Law (Law 09-08), supervised by the independent CNDP (Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel). The legislative model is the former EU Directive 95/46/EC; principles are similar to the GDPR but retain a 'prior declaration/prior authorization' system. It applies to controllers processing personal data in Morocco and foreign entities outside Morocco that use processing means within Morocco (including servers, cookies, subcontractors) — so Chinese subsidiaries, representative offices, and digital platforms using local servers are all covered. All personal data processing must be declared to the CNDP before processing (standard low-risk = declaration déclaration; sensitive data/interconnection/cross-border transfer to insufficiently protected countries require prior authorization autorisation). Violations can incur fines of MAD 10,000–600,000, 3 months–4 years imprisonment, doubled for legal persons, and possible business suspension.

Key points

Procedure

  1. Map data processing activities (employees, customers, suppliers, visitors, etc.) and determine risk levels.
  2. Submit a prior declaration (déclaration) to the CNDP for low-risk standard processing; submit a prior authorization (autorisation) for high-risk/sensitive/cross-border processing.
  3. Develop privacy notices, consent mechanisms, and data subject rights response processes.
  4. Appoint and register a Moroccan representative for foreign companies.
  5. Cross-border transfers: sign SCCs or group BCRs and apply for CNDP authorization (if the destination lacks adequate protection).
  6. Establish technical and organizational security measures, retain records, and review periodically.

Hard requirements

Costs

CNDP filing fees (per official rates); lawyer/DPO service fees separateViolation fines MAD 10,000–600,000; serious cases 3 months–4 years imprisonment; legal persons doubled⏱ ⏱ Timeline:Authorization review generally about 2 months; filings must be completed before processing begins.

⚠ Common risks

  • Processing personal data without filing: criminal and administrative penalties
  • Cross-border transfer without CNDP authorization (including overseas cloud/SaaS): 1 year imprisonment + MAD 200,000 fine
  • Foreign companies without a Moroccan representative: missing contact, compliance gaps
  • Missing data subject rights responses: complaints and penalties
  • Assuming only EU GDPR applies while ignoring the extraterritorial effect of Law 09-08
Handbook

📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)

Applies to:Chinese entities processing personal data in Morocco (subsidiaries, representative offices, platforms using local servers), and group scenarios transferring Moroccan employee/customer data back to China or third countries.

Prerequisites

  • In-Morocco data processing activities and data subject categories identified (employees, customers, suppliers)
  • Knowledge of the extraterritorial effect of Law 09-08 (overseas entities using Moroccan means are covered)
  • CNDP filing route (declaration/authorization) planned
  • Cross-border transfers require SCC/BCR and authorization applications
  • Foreign companies must appoint a Moroccan representative
StepActionOwnerTimelineCostOfficial form / systemNotes & penalties
1Data processing mapping.
Inventory all in-Morocco personal data processing (recruitment, HR, customer CRM, suppliers, visitors, monitoring); determine whether sensitive data, interconnection, or cross-border transfers are involved; assess risk levels and filing types.
In-Morocco legal/compliance + China data protection team1–2 weeksInternal costRecord of processing activities (RoPA)Group HR data returned to HQ and overseas cloud use both count as transfers.
Penalty:Missed sensitive/cross-border cases lead to unauthorized processing and criminal penalties.
2CNDP filing (declaration or authorization).
Standard low-risk processing submits a prior declaration (déclaration) to the CNDP; sensitive data, interconnection, and cross-border transfers to insufficiently protected countries submit a prior authorization (autorisation) with safeguards. Authorization review about 2 months; silence is deemed refusal.
In-Morocco compliance + CNDPDeclaration weeks; authorization about 2 monthsCNDP fees; advisor feesCNDP declaration/authorization applicationFiling must be completed before processing begins.
Penalty:Processing without filing: fines MAD 10,000–600,000; criminal liability in serious cases.
3Appoint a Moroccan representative.
Foreign companies without an establishment in Morocco but covered by the law must appoint a natural or legal person as the Moroccan representative, serving as the CNDP and data subject contact point, identified in the filing.
Chinese parent + local representative1 weekRepresentative service feesRepresentative appointment; CNDP registrationCommonly a local subsidiary, accounting firm, or law firm.
Penalty:No representative means missing contact, compliance gaps, and penalties.
4Privacy notices and consent mechanisms.
Establish transparent notices (purpose, basis, recipients, retention) and valid consent mechanisms (explicit consent for sensitive data); implement access (within 10 days), rectification, blocking, and objection rights responses.
In-Morocco compliance + IT2–4 weeksInternal costPrivacy policy; consent records; rights response SOPConsent must be provable and revocable.
Penalty:Missing rights responses trigger complaints and penalties.
5Cross-border transfer compliance (SCC/BCR + authorization).
Before transferring Moroccan data to China/third countries: assess destination adequacy (EU generally deemed adequate); non-adequate destinations require SCC or group BCR safeguards and CNDP prior authorization. Overseas cloud/SaaS also constitutes a transfer requiring SCC and filing.
In-Morocco compliance + China data team + CNDPAuthorization about 2 monthsLegal document drafting; CNDP feesSCC/BCR; CNDP cross-border authorizationChina is generally not listed as adequately protected; authorization is required.
Penalty:Unauthorized cross-border transfer: 1 year imprisonment + MAD 200,000 fine; controller fully liable.
6Security and ongoing review.
Implement technical and organizational security measures (access control, encryption, retention minimization), retain processing records, periodically review filings and measures, and update authorizations promptly.
In-Morocco IT/complianceOngoingOperations costSecurity baseline and records; annual reviewBusiness/system changes require synchronized filing updates.
Penalty:Missing measures aggravate breach penalties.

✅ Self-check list

⚠ Common pitfalls

Assuming only GDPR applies影响:Ignoring the extraterritorial effect of Law 09-08 and the prior-filing system; criminal penalties.规避:Benchmark Law 09-08; CNDP filing is a hard prerequisite.
Cross-border transfer without CNDP authorization影响:1 year imprisonment + MAD 200,000 fine; controller fully liable.规避:Sign SCC/BCR and obtain CNDP authorization before transferring to non-adequate countries such as China.
No Moroccan representative appointed影响:Missing contact, compliance gaps, and penalties.规避:Foreign companies without an establishment appoint a local representative and list it in filings.
Sensitive data without prior authorization影响:Unauthorized processing triggers criminal liability.规避:Apply separately for authorization for health/biometric/union etc. sensitive processing.
Overseas cloud/SaaS not reported as a transfer影响:Constitutes unauthorized cross-border transfer.规避:Include all overseas-hosted SaaS/cloud in transfer filings with SCC.

📅 Ongoing post-incorporation obligations

  • Keep CNDP declarations/authorizations valid and updated with business changes
  • Respond to data subject rights requests promptly
  • Renew cross-border transfer authorizations on expiry
  • Periodically review security measures and processing records
  • Update representative information registrations on changes

🔗 Official portals

📎 Source:Moroccan Personal Data Protection Law Law 09-08 (promulgated 2009-02-18, implementing decree 2-09-165, fully effective 2011-03-16); National Personal Data Protection Control Commission (CNDP); DPO Consulting / Korte Law / Upsilon Consulting Morocco data compliance guides
Want to turn this into an actionable compliance workflow?

CompliGo · Outbound Compliance Automation

You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.

CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.