MA

Morocco

North Africa

10Instruments
0Cases
3Regulators
65%Coverage
Overview

Morocco regulates personal data through Law No. 09-08 on the protection of individuals with regard to the processing of personal data, promulgated by Dahir No. 1-09-15 of 18 February 2009, Morocco's first comprehensive data protection statute and one of the earliest in North Africa. After a two-year transition while the regulator stood up, full enforcement began on 16 March 2011. The law applies to processing by controllers established in Morocco or using means located there, public and private, excluding purely private processing. Controllers must observe the core data-quality principles and generally rely on prior consent, with derogations for legal obligation, contract, vital interests, public-interest tasks, and legitimate interests. Sensitive data (racial or ethnic origin, political opinions, religious belief, health, sexual life) is prohibited in principle, with limited exceptions including express consent and regulator authorisation. Processing requires a prior declaration to the regulator, and prior authorisation for sensitive data, cross-border transfers, and high-risk operations. Data subjects have rights of prior information, access, rectification, and objection, with an absolute right to object to direct marketing. Cross-border transfers are permitted only to adequate countries or with authorisation. Enforcement rests with the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP), an independent authority that receives declarations and authorisations, issues opinions, investigates and inspects, imposes sanctions, and authorises transfers. Notably, since 2025 the CNDP has intensified enforcement through targeted sectoral campaigns, marking a shift from awareness-raising to active compliance action. Having legislated in 2009 with a continuously operating regulator now moving into active enforcement, Morocco runs one of the more established regimes in its region.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection10
AI Governance20
Fintech40
Cybercrime10
Digital Rights20
Platform Liability00
Telecoms00

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
ma-const-privacy·Act

Constitution of the Kingdom of Morocco, 2011, Articles 24, 25 and 27 (Privacy of communications, freedom of expression and right to information)

MoroccoDigital RightsIn Force
Verified

Enacted 29 Jul 2011

ma-digitalrights-presscode-2016·Act

Loi n° 88-13 relative à la presse et à l'édition (Law No. 88-13 on the Press and Publishing) (Morocco)

MoroccoDigital RightsIn Force
Verified

Enacted 10 Aug 2016

ma-cyber-2003·Act

Loi n° 07-03 complétant le code pénal en ce qui concerne les infractions relatives aux systèmes de traitement automatisé des données (Law No. 07-03 supplementing the Penal Code regarding offences relating to automated data processing systems)

MoroccoCybercrimeIn Force
Verified

Enacted 11 Nov 2003

ma-fintech-mobilepay-2018·Guidance

Cadre réglementaire du paiement mobile domestique de Bank Al-Maghrib (2018), décision réglementaire et lettre circulaire (Bank Al-Maghrib Domestic Mobile Payment Regulatory Framework (2018), regulatory decision and circular letter)

MoroccoFintechIn Force
Verified

Enacted 1 Nov 2018

ma-fintech-guide-2025·Guidance

Guide de Bank Al-Maghrib sur le parcours réglementaire des porteurs de projets fintech (2025) (Bank Al-Maghrib Guide on the Regulatory Pathway for Fintech Project Holders (2025))

MoroccoFintechIn Force
Verified

Enacted 1 Dec 2025

ma-fintech-licensing-2015·Guidance

Circulaire du Wali de Bank Al-Maghrib n° 5/W/15 du 20 mai 2015 relative aux documents et renseignements nécessaires à l'instruction des demandes d'agrément des établissements de paiement (Circular No. 5/W/15 of 20 May 2015 on the documents and information required to process payment institution licensing applications)

MoroccoFintechIn Force
Verified

Enacted 20 May 2015

ma-fintech-payinst-2014·Act

Loi n° 103-12 relative aux établissements de crédit et organismes assimilés, régime des établissements de paiement (Law No. 103-12 on Credit Institutions and Similar Bodies, Payment Institutions regime)

MoroccoFintechIn Force
Verified

Enacted 24 Dec 2014

ma-ai-2026·Guidance

Maroc IA 2030, National Artificial Intelligence Roadmap ("AI Made in Morocco")

MoroccoAI GovernanceProposed
Verified

Enacted 12 Jan 2026

ma-ai-bill-2024·Draft Bill

Proposition de loi portant création de l'Agence Nationale de l'Intelligence Artificielle (Draft Law establishing the National Agency for Artificial Intelligence) (Morocco)

MoroccoAI GovernanceDraft
Verified

Enacted 17 Apr 2024

ma-dp-2009·Act

Loi n° 09-08 relative à la protection des personnes physiques à l’égard du traitement des données à caractère personnel (Law No. 09-08 on the Protection of Individuals with regard to the Processing of Personal Data)

MoroccoData ProtectionIn Force
Verified

Enacted 18 Feb 2009

Notable gaps

The 2009 law predates the GDPR generation and lacks, on its face, a fixed statutory breach-notification deadline, a general DPO mandate, and portability and modern erasure rights. ATLPF holds the primary law but no separate implementing decrees.