Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
Law 09-08
Morocco's Law 09-08 (2009) is one of Africa's earliest comprehensive data protection laws, built on a prior declaration and authorisation model administered by the CNDP and backed by criminal fines and imprisonment.
Law 09-08 was promulgated on 18 February 2009 and implemented by Decree No. 2-09-165 of 21 May 2009. It created the CNDP (Commission Nationale de controle de la protection des Donnees a caractere Personnel), which informs, advises, controls and sanctions, and verifies that processing is lawful and does not infringe privacy or fundamental rights. The regime is filing-based: all processing requires a prior declaration to the CNDP, and prior authorisation is required for sensitive data (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health and genetic data), purpose changes, offence and conviction data, and data including the national ID number. No processing may start before the CNDP issues its receipt or authorisation.
Cross-border transfers require prior CNDP authorisation and an adequate level of protection in the destination country, with consent and other narrow exceptions. Direct electronic marketing without prior express consent is prohibited, subject to an existing-customer exception. There is no general DPO requirement and no breach-notification duty under the law itself. In 2025 the CNDP announced the deployment of a dark web monitoring tool, built with a cybersecurity firm, to detect unlawful publication of personal data and identify controllers that failed to declare their processing. Morocco has ratified Council of Europe Convention 108 and its modernised version and operates a national data protection register.
Every processing operation must be declared to the CNDP before it begins; processing without the CNDP's receipt is unlawful.
Sensitive data, purpose changes, genetic data, offence and conviction data and data containing the national ID number require prior CNDP authorisation.
Processing generally requires the data subject's prior consent; data must be collected for specified, explicit, legitimate purposes and be adequate, accurate and up to date.
Any transfer abroad requires CNDP authorisation and an adequate level of protection in the recipient state, with limited exceptions such as express consent, legal obligation, contract or vital interests.
Read more
Anove scans your stack against Law 09-08 and 260+ other frameworks in minutes.
Controllers must implement all technical and organisational measures to prevent damage, alteration or unauthorised third-party access, and must choose processors offering sufficient guarantees.