Morocco Law 09-08

Morocco's data-protection law: the CNDP's declaration and authorisation regime.

Market regime · Law No. 09-08 on the protection of personal data (Morocco)

Issued by

Kingdom of Morocco

Region

Morocco

Effective

2009, with the CNDP operational since 2011

Oversight

CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel)

Applies when

You process personal data in Morocco

In the catalog

Curated, versioned & cross-mapped

The obligation, plainly.

Law 09-08 established Morocco's data-protection regime around the CNDP and a distinctive procedural model: processing is declared to the commission, and sensitive categories and cross-border transfers require prior authorisation rather than self-assessment.

It predates the GDPR era, so its obligations are more procedural than principle-based, and reform discussions have been long-running. The catalog curates the law as it operates, declarations, authorisations, security duties, with the shared privacy controls carrying the substance.

Where programmes are tested.

01

Declarations to the CNDP

Processing operations declared before they begin, and kept current.

02

Prior authorisations

Sensitive-data processing and cross-border transfers authorised, not assumed.

03

Security and rights

Security obligations and data-subject rights honoured under the law's terms.

Curated once, evidenced continuously.

  • The law's procedural regime is modelled explicitly, declaration and authorisation as first-class requirements, mapped to the same privacy controls the rest of the portfolio runs on.
  • Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
  • Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
  • Every attestation carries maker/checker, and every action lands in an append-only audit trail.

Morocco Law 09-08, asked plainly.

The questions compliance teams actually ask before an adoption decision or an audit.

How is Morocco's regime different from GDPR-style laws?

It is procedural at its core: declare processing to the CNDP, and obtain prior authorisation for sensitive data and transfers. Accountability regimes ask you to self-assess and document; 09-08 asks you to file, which changes the operational workflow.

Do cross-border transfers need approval?

Yes, transfers out of Morocco generally require CNDP authorisation unless the destination assures adequate protection. Transfer mapping and authorisation evidence therefore sit at the front of the compliance file.

Is the law being modernised?

Reform toward a GDPR-aligned regime has been discussed for years. We curate the law in force, and the overlay model means a successor act would arrive as a new version to adopt deliberately, not a silent rewrite.

Where it connects.

The full catalog
Cross-mapped with

Compliance you can prove.
Walk into your next audit ready.

Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.

The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.