Loi n° 07-03 complétant le code pénal en ce qui concerne les infractions relatives aux systèmes de traitement automatisé des données (Law No. 07-03 supplementing the Penal Code regarding offences relating to automated data processing systems)
ma-cyber-2003 · Act
Law No. 07-03, promulgated by Dahir No. 1-03-197 of 11 November 2003 and published in Bulletin Officiel No. 5184 of 5 February 2004, is Morocco's foundational cybercrime statute. Rather than standing alone, it supplements the Penal Code by inserting a dedicated chapter (Articles 607-3 to 607-11) on offences relating to automated data processing systems (systèmes de traitement automatisé des données, STAD). It was Morocco's first instrument to introduce the concept of cybercrime into domestic criminal law and remains the core text for prosecuting computer-based offences. The law criminalises the full range of offences against the confidentiality, integrity and availability of computer systems and data. Fraudulent access to all or part of an automated data processing system is an offence (Article 607-3), as is fraudulently remaining within such a system. The law separately penalises conduct that hinders or distorts the functioning of a system, and the fraudulent introduction, deletion, alteration or modification of data. It also addresses the forgery and use of forged electronic documents capable of causing harm. Penalties are graduated according to the seriousness of the conduct and its consequences. Basic fraudulent access is punishable by one to three months' imprisonment and a fine of 2,000 to 10,000 dirhams. Penalties increase where the intrusion results in the deletion or modification of data or in impaired system operation. The offence is aggravated where the targeted system is presumed to contain information relating to the internal or external security of the State, or secrets concerning the national economy, reflecting the law's concern with critical and sensitive systems. The law also penalises preparatory and facilitation conduct, including the manufacture, procurement or supply of tools and programs designed to commit the listed offences, and provides for attempts to be punished as the completed offence. As a Penal Code amendment, Law 07-03 is enforced through the ordinary criminal justice system, the public prosecutor, investigating judges and the courts, rather than a dedicated cyber agency. It now operates alongside Morocco's wider digital legal framework, including Law No. 09-08 on personal data protection (2009) and Law No. 05-20 on cybersecurity (2020), the latter establishing institutional cybersecurity governance under the DGSSI. Law 07-03 nonetheless remains the principal source of substantive cybercrime offences in Moroccan law.
- Inserts a dedicated cybercrime chapter (Arts 607-3 to 607-11) into the Penal Code, introducing the concept of offences against automated data processing systems (STAD)
- Criminalises fraudulent access to, and fraudulently remaining within, all or part of a computer system (Art 607-3)
- Penalises obstructing or distorting system functioning and the fraudulent input, deletion, alteration or modification of data
- Provides aggravated penalties where data is deleted/altered, system operation is impaired, or the system holds State-security or national-economy information
- Punishes the manufacture, procurement or supply of tools/programs designed to commit the listed offences, and treats attempts as the completed offence
- Enforced through the ordinary criminal justice system; operates alongside Law 09-08 (data protection) and Law 05-20 (cybersecurity)