MoroccoIn ForceData Protection

Loi n° 09-08 relative à la protection des personnes physiques à l’égard du traitement des données à caractère personnel (Law No. 09-08 on the Protection of Individuals with regard to the Processing of Personal Data)

ma-dp-2009 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

Law No. 09-08 on the Protection of Individuals with regard to the Processing of Personal Data (Loi n° 09-08) is Morocco’s foundational data protection statute. Promulgated by Dahir No. 1-09-15 of 18 February 2009 and published in the Bulletin Officiel No. 5714 of 5 March 2009, it represents Morocco’s first comprehensive legislative framework for personal data protection. A two-year transition period applied while the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) became operational, with full enforcement commencing 16 March 2011. The law remains in force. The law applies to all processing of personal data by a controller established in Morocco or using processing means located in Morocco, excluding processing carried out exclusively for private purposes. It covers both automated processing and manual processing in structured filing systems, applying equally to public and private entities. Personal data is defined as any information, in any form, that allows the direct or indirect identification of a natural person. Controllers must comply with core data quality principles: processing must be lawful and fair; data must be collected for specified, explicit, and legitimate purposes; data must be adequate, relevant, and not excessive; data must be accurate and, where necessary, kept up to date; and retention must be limited to what is necessary. Prior consent of the data subject is the general basis for processing, with derogations for legal obligations, contractual necessity, protection of vital interests, public interest tasks, and the legitimate interests of the controller. Processing of sensitive data, including racial or ethnic origin, political opinions, religious beliefs, health data, and sexual life, is prohibited as a general rule, with limited exceptions including the data subject’s express consent and CNDP authorisation. Processing of data relating to criminal offences and penalties is reserved for judicial authorities and authorised public bodies. Controllers must file a declaration with the CNDP before commencing standard processing operations. Prior CNDP authorisation is required for processing of sensitive data, cross-border transfers, and other high-risk operations designated by law. The CNDP may object to a declared processing operation within thirty days of receiving a declaration. Data subjects enjoy rights of prior information, access, rectification, and objection. The right to object to direct marketing is absolute. Controllers must inform data subjects of the identity of the controller, processing purposes, and recipients at the time of collection. Cross-border transfers are permitted only to countries ensuring adequate protection or subject to CNDP authorisation on a case-by-case basis. The CNDP is empowered to conduct on-site investigations, issue formal notices and injunctions, and impose administrative sanctions. Criminal penalties apply to serious violations. Since 2025, the CNDP has significantly intensified enforcement through targeted sectoral campaigns, signalling a shift from awareness-raising to active compliance action.

Key provisions
  1. Prior declaration to CNDP required for standard processing; prior CNDP authorisation required for sensitive data processing, cross-border transfers, and high-risk processing designated by law
  2. Processing of sensitive data (racial/ethnic origin, health, religious beliefs, sexual life) prohibited in principle; exceptions include data subject’s express consent and CNDP authorisation
  3. Data subject rights include prior information, access, rectification, erasure, and objection; right to object to direct marketing is absolute
  4. Cross-border transfers permitted only to countries ensuring adequate protection or subject to CNDP authorisation
  5. Controllers must implement appropriate technical and organisational security measures against accidental or unlawful destruction, alteration, and unauthorised access or disclosure
  6. Processing of criminal convictions and offences data reserved for judicial authorities and authorised public bodies
  7. CNDP empowered to conduct on-site investigations, issue injunctions, and refer criminal violations for prosecution
Entry history
Entry history
  1. 23 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from CNDP official publication of Law 09-08 (Bulletin Officiel No. 5714, 5 March 2009) and DLA Piper Data Protection Laws of the World, Morocco