Morocco Law 09-08
Market regime · Law No. 09-08 on the protection of personal data (Morocco)
Kingdom of Morocco
Morocco
2009, with the CNDP operational since 2011
CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel)
You process personal data in Morocco
Curated, versioned & cross-mapped
The obligation, plainly.
Law 09-08 established Morocco's data-protection regime around the CNDP and a distinctive procedural model: processing is declared to the commission, and sensitive categories and cross-border transfers require prior authorisation rather than self-assessment.
It predates the GDPR era, so its obligations are more procedural than principle-based, and reform discussions have been long-running. The catalog curates the law as it operates, declarations, authorisations, security duties, with the shared privacy controls carrying the substance.
Where programmes are tested.
Declarations to the CNDP
Processing operations declared before they begin, and kept current.
Prior authorisations
Sensitive-data processing and cross-border transfers authorised, not assumed.
Security and rights
Security obligations and data-subject rights honoured under the law's terms.
Curated once, evidenced continuously.
- The law's procedural regime is modelled explicitly, declaration and authorisation as first-class requirements, mapped to the same privacy controls the rest of the portfolio runs on.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
Morocco Law 09-08, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
How is Morocco's regime different from GDPR-style laws?
It is procedural at its core: declare processing to the CNDP, and obtain prior authorisation for sensitive data and transfers. Accountability regimes ask you to self-assess and document; 09-08 asks you to file, which changes the operational workflow.
Do cross-border transfers need approval?
Yes, transfers out of Morocco generally require CNDP authorisation unless the destination assures adequate protection. Transfer mapping and authorisation evidence therefore sit at the front of the compliance file.
Is the law being modernised?
Reform toward a GDPR-aligned regime has been discussed for years. We curate the law in force, and the overlay model means a successor act would arrive as a new version to adopt deliberately, not a silent rewrite.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.