🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
MA v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing11 sources retrieved model claude-sonnet-5 · 2026-08-05

Morocco

MA schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 26 claims · 22 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
26Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Morocco's data-protection enforcement posture has begun to tighten this cycle. According to Chambers and Partners' practice-guide reporting, the CNDP has, over the last several months, started issuing warnings to major data controllers and has initiated investigations into potential violations by controllers processing significant volumes of personal data. This marks a shift from what has historically been a largely dormant sanctioning record toward an active warnings-and-investigations posture, even though the underlying statute, Law 09-08, has not itself been amended.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus law and operational regulator exist, but gap-analysis-identified limits on CNDP powers and unconfirmed territorial scope pull the rating down from green.

Primary frameworkLaw No. 09-08 of 18 February 2009 on the Protection of Individuals with regard to the Processing of Personal Data, and Implementing Decree No. 2-09-165 of 21 May 2009
Traffic-light rationale — AmberComprehensive omnibus law and operational regulator exist, but gap-analysis-identified limits on CNDP powers and unconfirmed territorial scope pull the rating down from green.

Sub-modules (5)

Regulator And AuthorityGreen

CNDP is the designated national supervisory authority under Law 09-08.

Claims (1):

  • The Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) is Morocco's national data protection supervisory authority responsible for overseeing compliance with Law No. 09-08.

Act And InstrumentsAmber

Primary instrument is Law 09-08 plus its 2009 implementing decree; CNDP has periodically announced reform/modernisation plans.

Claims (2):

  • Personal data protection in Morocco is governed by Law n° 09-08 of 18 February 2009 relating to the protection of individuals with respect to the processing of personal data, and its Implementation Decree n° 2-09-165 of 21 May 2009.
  • In March 2020, CNDP announced measures including plans to revise national data protection laws and promote privacy-by-design, alongside internal reorganisation to speed up processing of notifications.

Material ScopeGreen

Gap analysis found material scope broadly convergent with GDPR definitions and principles.

Claims (1):

  • A Morocco-EU gap-analysis study found convergence between Law 09-08 and the GDPR on definitions, material scope of the law, and the principles of data processing.

Territorial ScopeAmber

No sourced evidence located on extraterritorial application to non-established controllers; searched 'Law 09-08 territorial scope non-established controllers' without a confirmed dedicated provision.

Claims (3):

  • CLM-MA-c48f2e91 (claim on file)
  • CLM-MA-c48f2e91 (claim on file)
  • CLM-MA-c48f2e91 (claim on file)

Regulator Registration And FilingAmber

CNDP opened a national data-protection register/filing platform for controllers.

Claims (1):

  • CNDP opened a national data protection register for controller filings/notifications.
Category narrative69 words

Morocco's data protection regime rests on Law n° 09-08 of 18 February 2009 and its Implementing Decree n° 2-09-165 of 21 May 2009, supervised by the CNDP. A 2018 Morocco-EU gap-analysis study found convergence with the GDPR on definitions, material scope and processing principles, but flagged limits on CNDP's powers. No sourced evidence was found on express extraterritorial/non-established-controller scope; searched 'CNDP territorial scope non-established controllers' yielded no dedicated provision.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedDataGuidance — The Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) is Morocco's national data protection supervisory authority responsible for overseeing compliance with Law No. 09-08.observed
  2. ConfirmedIAPP — Personal data protection in Morocco is governed by Law n° 09-08 of 18 February 2009 relating to the protection of individuals with respect to the processing of personal data, and its Implementation Decree n° 2-09-165 of 21 May 2009.observed
  3. ConfirmedDataGuidance — In March 2020, CNDP announced measures including plans to revise national data protection laws and promote privacy-by-design, alongside internal reorganisation to speed up processing of notifications.observed
  4. ProbableIAPP — A Morocco-EU gap-analysis study found convergence between Law 09-08 and the GDPR on definitions, material scope of the law, and the principles of data processing.observed
  5. ProbableIAPP — CNDP opened a national data protection register for controller filings/notifications.observed

#

Core principles exist but consent standards and special-category coverage materially diverge from GDPR-equivalent baselines.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberCore principles exist but consent standards and special-category coverage materially diverge from GDPR-equivalent baselines.

Sub-modules (4)

Lawful BasesAmber

Gap analysis found convergence on general processing principles, though not a GDPR Article-6-style enumerated lawful-bases list.

Claims (1):

  • A Morocco-EU gap analysis found convergence between Law 09-08 and the GDPR on the general principles of data processing, though without a GDPR Article-6-style enumerated list of lawful bases.

Special CategoriesRed

Law 09-08 does not reference biometric data or sexual orientation as special categories.

Claims (1):

  • The gap analysis identified the absence of references to biometric data or sexual orientation as protected special categories under Law 09-08, diverging from the GDPR's Article 9 special-category regime.

Pseudonymisation And AnonymisationRed

No sourced provisions found; searched 'Morocco 09-08 pseudonymisation anonymisation safe harbour' without result.

Category narrative50 words

Law 09-08's general processing principles were found broadly convergent with GDPR principles, but the same gap analysis identified material divergences: no detailed consent-validity conditions, and no biometric data or sexual-orientation categories among protected special categories. No sourced information was located on pseudonymisation/anonymisation safe-harbours; searched 'Law 09-08 pseudonymisation anonymisation' without result.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ProbableIAPP — A Morocco-EU gap analysis found convergence between Law 09-08 and the GDPR on the general principles of data processing, though without a GDPR Article-6-style enumerated list of lawful bases.observed
  2. ConfirmedIAPP — The Morocco-EU gap analysis found that Law 09-08 has no detailed conditions related to the validity of consent, unlike the GDPR's requirements for freely given, specific and informed consent.observed
  3. ConfirmedIAPP — The gap analysis identified the absence of references to biometric data or sexual orientation as protected special categories under Law 09-08, diverging from the GDPR's Article 9 special-category regime.observed

#

Core rights (access, rectification, objection) exist; erasure and portability are absent, and statutory deadlines are unconfirmed.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberCore rights (access, rectification, objection) exist; erasure and portability are absent, and statutory deadlines are unconfirmed.

Sub-modules (5)

Access RightAmber

Inferred as convergent with GDPR baseline since the gap analysis did not flag access rights as a divergence.

Claims (1):

  • Because the Morocco-EU gap analysis identified only the absence of a right to be forgotten and a right to data portability as divergences in data subject rights, rights of access, rectification and objection under Law 09-08 are inferred to be broadly convergent with the GDPR baseline.

Rectification And ErasureAmber

Rectification inferred as convergent; erasure/right-to-be-forgotten confirmed absent.

Claims (2):

  • Because the Morocco-EU gap analysis identified only the absence of a right to be forgotten and a right to data portability as divergences in data subject rights, rights of access, rectification and objection under Law 09-08 are inferred to be broadly convergent with the GDPR baseline.
  • Law 09-08 does not include a right to be forgotten/erasure right equivalent to GDPR Article 17.

Restriction And ObjectionAmber

Objection right inferred as convergent since not flagged as a divergence area.

Claims (1):

  • Because the Morocco-EU gap analysis identified only the absence of a right to be forgotten and a right to data portability as divergences in data subject rights, rights of access, rectification and objection under Law 09-08 are inferred to be broadly convergent with the GDPR baseline.

Data PortabilityRed

Data portability confirmed absent under Law 09-08.

Claims (1):

  • Law 09-08 does not provide data subjects a right to data portability, a gap identified relative to the GDPR.

Deadlines And Response WindowsRed

No sourced statutory response-window data found; searched 'CNDP data subject request deadline days' without result.

Category narrative71 words

Because the Morocco-EU gap analysis singled out only the absence of a right to be forgotten and a right to data portability as divergences in data subject rights, this indicates that access, rectification and objection rights under Law 09-08 are broadly convergent with the GDPR baseline; erasure and portability are confirmed gaps. No sourced information was found on statutory response-window deadlines; searched 'Law 09-08 CNDP subject access request deadline' without result.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ProbableIAPP — Because the Morocco-EU gap analysis identified only the absence of a right to be forgotten and a right to data portability as divergences in data subject rights, rights of access, rectification and objection under Law 09-08 are inferred to be broadly convergent with the GDPR baseline.observed
  2. ConfirmedIAPP — Law 09-08 does not provide data subjects a right to data portability, a gap identified relative to the GDPR.observed
  3. ConfirmedIAPP — Law 09-08 does not include a right to be forgotten/erasure right equivalent to GDPR Article 17.observed

#

Some accountability practice (DPIA guidance, breach-handling reminders) exists but core GDPR-equivalent duties (DPO, ROPA, retention) are unconfirmed or absent.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberSome accountability practice (DPIA guidance, breach-handling reminders) exists but core GDPR-equivalent duties (DPO, ROPA, retention) are unconfirmed or absent.

Sub-modules (7)

Accountability And DpiaAmber

CNDP published a decision setting DPIA-type assessment criteria.

Claims (1):

  • CNDP has published a decision setting out criteria for when a Data Protection Impact Assessment-type assessment is required for certain processing operations.

Dpo RequirementsRed

No sourced evidence of a statutory DPO appointment threshold; searched 'Morocco 09-08 DPO requirement' without result.

Ropa RequirementsRed

No sourced ROPA/records-of-processing requirement found; searched 'CNDP registre des traitements' without result.

Joint Controller ArrangementsRed

No sourced joint-controller provisions found.

Security MeasuresRed

No sourced technical/organisational security-measure specifics found.

Breach NotificationAmber

Gap analysis found no codified breach-notification duty; CNDP has nonetheless issued practical reminders to controllers on breach procedure.

Claims (2):

  • The Morocco-EU gap analysis found that Law 09-08 lacks a requirement to notify the supervisory authority of personal data breaches, a divergence from the GDPR's Articles 33-34 breach-notification regime.
  • CNDP has issued reminders to controllers regarding data-breach handling procedures notwithstanding the absence of a codified statutory breach-notification obligation.

Retention And DisposalRed

No sourced retention/disposal limits found; searched 'Law 09-08 data retention limits' without result.

Category narrative75 words

CNDP has published a decision setting criteria for DPIA-type assessments and has issued reminders to controllers on data-breach handling procedures, notwithstanding the gap analysis finding that Law 09-08 imposes no codified statutory breach-notification duty to the regulator. No sourced evidence was found on DPO appointment thresholds, ROPA requirements, joint-controller arrangements, technical/organisational security-measure specifics, or retention/disposal limits; searched 'Law 09-08 DPO requirement', 'CNDP ROPA registre des traitements', and 'Law 09-08 data retention limits' without confirmed results.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ProbableDataGuidance — CNDP has published a decision setting out criteria for when a Data Protection Impact Assessment-type assessment is required for certain processing operations.observed
  2. ConfirmedIAPP — The Morocco-EU gap analysis found that Law 09-08 lacks a requirement to notify the supervisory authority of personal data breaches, a divergence from the GDPR's Articles 33-34 breach-notification regime.observed
  3. ProbableDataGuidance — CNDP has issued reminders to controllers regarding data-breach handling procedures notwithstanding the absence of a codified statutory breach-notification obligation.observed

#

A transfer mechanism and authorisation process exist, but EU adequacy remains unresolved and SCC/BCR/localisation instruments are unconfirmed.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberA transfer mechanism and authorisation process exist, but EU adequacy remains unresolved and SCC/BCR/localisation instruments are unconfirmed.

Sub-modules (6)

Transfer MechanismsAmber

Trans-border transfer principles found convergent with GDPR; CNDP operates an expedited transfer-authorisation process.

Claims (2):

  • Law 09-08's principles applicable to trans-border data transfers were found to converge with the GDPR's approach in a Morocco-EU gap analysis.
  • CNDP approved an expedited process to authorise certain cross-border personal data transfers.

Adequacy ReceivedAmber

Morocco's 2009 EU adequacy request remains pending as of the most recent reported review.

Claims (1):

  • Morocco requested an EU adequacy recognition decision as early as 2009, and this request remains reported as pending.

Adequacy GrantedRed

No sourced evidence Morocco has granted adequacy status to other regimes; searched 'Morocco adequacy decision granted third country' without result.

Sccs And BcrsRed

No sourced SCC/BCR framework found under Moroccan law.

Transfer Impact AssessmentRed

No sourced TIA requirement found.

Data LocalisationRed

No sourced data-localisation mandate found.

Category narrative79 words

Law 09-08's principles applicable to trans-border data transfers were found convergent with the GDPR approach, and CNDP has approved an expedited authorisation process for certain transfers. Morocco requested EU adequacy recognition as early as 2009 and this request remains reported as pending. No sourced evidence was found on SCC/BCR forms, transfer-impact-assessment requirements, data-localisation mandates, or adequacy decisions granted by Morocco to other regimes; searched 'CNDP SCC BCR', 'Morocco data localisation law', and 'Morocco adequacy decision granted' without confirmed results.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ConfirmedIAPP — Morocco requested an EU adequacy recognition decision as early as 2009, and this request remains reported as pending.observed
  2. ProbableIAPP — Law 09-08's principles applicable to trans-border data transfers were found to converge with the GDPR's approach in a Morocco-EU gap analysis.observed
  3. ProbableDataGuidance — CNDP approved an expedited process to authorise certain cross-border personal data transfers.observed

#

Only one sub-module (health, via genomic-data recommendations) has sourced evidence; the remaining six sub-modules carry no confirmed sectoral overlay.

Supervisory authorityCNDP
Traffic-light rationale — RedOnly one sub-module (health, via genomic-data recommendations) has sourced evidence; the remaining six sub-modules carry no confirmed sectoral overlay.

Sub-modules (7)

Financial Sector OverlayRed

No sourced financial-sector DP overlay found; searched 'CNDP secteur bancaire données personnelles' without result.

Health Sector OverlayAmber

CNDP has presented recommendations specifically addressing genomic data processing.

Claims (1):

  • CNDP has presented recommendations specifically addressing the processing of genomic data.

Telecoms And EprivacyRed

No sourced telecoms/ePrivacy-equivalent regime found; searched 'Morocco telecoms ePrivacy cookies law' without result.

Employment DataRed

No sourced employment-data-specific rules found.

Credit And ScoringRed

No sourced credit-scoring rules found.

EducationRed

No sourced education-sector-specific DP rules found beyond general awareness initiatives.

InsuranceRed

No sourced insurance-sector DP rules found.

Category narrative62 words

Sourced sectoral evidence is limited to CNDP recommendations on genomic/genetic data processing (health sector). No sourced overlays were found for financial services, telecoms/ePrivacy, employment, credit-scoring, education, or insurance sectors; searched 'CNDP secteur bancaire données personnelles', 'Morocco telecoms ePrivacy cookies law', 'CNDP employment data guidance', 'Morocco credit scoring data protection', 'CNDP education sector data', and 'Morocco insurance sector data protection' without confirmed results.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ProbableDataGuidance — CNDP has presented recommendations specifically addressing the processing of genomic data.observed

#

No comprehensive or sector-specific adtech/commercial-privacy regime was identified for this JID beyond the general data protection law.

Traffic-light rationale — Not assessedNo comprehensive or sector-specific adtech/commercial-privacy regime was identified for this JID beyond the general data protection law.

Sub-modules (6)

Cookies And TrackersRed

No sourced cookie/tracker-specific consent regime found.

Dark PatternsRed

No sourced dark-pattern prohibition found.

Opt Out SignalsRed

No sourced recognition of opt-out signals (e.g., GPC/DAA) found.

Clean Rooms And DcrRed

No sourced clean-room/data-collaboration-room rules found.

Cross Context AdvertisingRed

No sourced cross-context-advertising-specific regime found.

Direct MarketingRed

No sourced direct-marketing consent/suppression regime distinct from general law found.

Category narrative58 words

No sourced evidence was found of a Moroccan cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition (e.g. GPC), clean-room/data-collaboration rules, cross-context-advertising regime, or direct-marketing consent/suppression framework distinct from the general provisions of Law 09-08. Searched 'Morocco cookie law consent', 'CNDP dark patterns', 'Morocco Global Privacy Control', 'CNDP direct marketing opt-out', and 'Morocco data clean room regulation' without confirmed results.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

Biometric data is confirmed excluded from special-category protection and most sub-modules (profiling, ADM transparency, AI risk assessment, surveillance carve-outs) carry no sourced findings.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — RedBiometric data is confirmed excluded from special-category protection and most sub-modules (profiling, ADM transparency, AI risk assessment, surveillance carve-outs) carry no sourced findings.

Sub-modules (6)

Profiling RestrictionsRed

No sourced profiling-restriction provisions found; searched 'Law 09-08 profiling restrictions' without result.

Automated Decision Making TransparencyRed

No sourced ADM transparency/explanation-right provisions found.

Ai Risk AssessmentsRed

No sourced AI-specific risk-assessment regime found.

Biometric RegimeRed

Biometric data is confirmed absent from Law 09-08's special-category definitions.

Claims (1):

  • The Morocco-EU gap analysis found that Law 09-08 does not include biometric data within its special-category definitions, unlike GDPR Article 9.

Genetic DataAmber

CNDP has issued recommendations on genomic data despite no dedicated statutory genetic-data category.

Claims (1):

  • CNDP has issued recommendations concerning genomic data processing, indicating regulatory attention to genetic data despite the absence of a dedicated statutory genetic-data category in Law 09-08.

State Surveillance CarveoutsRed

No sourced state-surveillance carve-out provisions found; searched 'Law 09-08 national security exemption' without result.

Category narrative72 words

The Morocco-EU gap analysis found that Law 09-08 does not include biometric data within its special-category definitions, and CNDP has issued recommendations on genomic/genetic data despite no dedicated statutory genetic-data category. No sourced evidence was found on profiling restrictions, automated-decision-making transparency/explanation rights, AI-specific risk assessments, or state-surveillance carve-outs; searched 'Law 09-08 profiling restrictions', 'Morocco automated decision making transparency', 'Morocco AI Act risk assessment', and 'Law 09-08 national security exemption' without confirmed results.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedIAPP — The Morocco-EU gap analysis found that Law 09-08 does not include biometric data within its special-category definitions, unlike GDPR Article 9.observed
  2. ProbableDataGuidance — CNDP has issued recommendations concerning genomic data processing, indicating regulatory attention to genetic data despite the absence of a dedicated statutory genetic-data category in Law 09-08.observed

#

Only an awareness/education initiative is sourced; no statutory age-verification, parental-consent, minor-profiling-ban, or dependent-adult provisions were confirmed.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — RedOnly an awareness/education initiative is sourced; no statutory age-verification, parental-consent, minor-profiling-ban, or dependent-adult provisions were confirmed.

Sub-modules (5)

Age VerificationRed

No sourced statutory age-of-consent/age-verification mechanism found.

Minor Profiling BansRed

No sourced minor-profiling-ban provisions found.

Education SettingsAmber

CNDP launched an awareness platform for children, parents, guardians and teachers on digital privacy.

Claims (1):

  • CNDP launched the 'Koun3labal' platform to raise awareness among children, adolescents, parents, guardians and teachers about digital privacy opportunities, dangers, risks, rights and remedies.

Dependent AdultsRed

No sourced dependent-adult protection provisions found; searched 'CNDP dependent adults data protection' without result.

Category narrative62 words

No statutory age-of-consent, parental-consent mechanism, or minor-profiling ban was found under Law 09-08. CNDP has, however, launched an awareness platform ('Koun3labal') targeting children, adolescents, parents, guardians and teachers on digital privacy risks and rights. No sourced evidence was found on dependent-adult protections; searched 'Morocco age of digital consent minors', 'Law 09-08 parental consent', and 'CNDP dependent adults data protection' without confirmed results.

Sources and claims (1)
  1. ConfirmedIAPP — CNDP launched the 'Koun3labal' platform to raise awareness among children, adolescents, parents, guardians and teachers about digital privacy opportunities, dangers, risks, rights and remedies.observed

#

Institutional enforcement cooperation and international engagement exist, but CNDP's statutory powers are reportedly limited and collective-redress/private-right-of-action mechanisms are unconfirmed.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberInstitutional enforcement cooperation and international engagement exist, but CNDP's statutory powers are reportedly limited and collective-redress/private-right-of-action mechanisms are unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Gap analysis found limits on CNDP's statutory powers; CNDP participates in international regulatory cooperation.

Claims (2):

  • The Morocco-EU gap analysis identified limits on the powers granted to CNDP as an area of divergence from the GDPR's enforcement framework for supervisory authorities.
  • CNDP was among 12 data protection authorities from six continents that signed a joint statement addressed to major social media companies in August 2023.

Enforcement Activity IndexAmber

CNDP and the Public Ministry agreed a collaborative enforcement roadmap in January 2019.

Claims (1):

  • CNDP and Morocco's Public Ministry agreed in January 2019 on a collaborative roadmap including a case-tracking system and a dedicated prosecution unit for data-protection cases referred by CNDP.

Regulator Funding And CapacityRed

Commentary (opinion-tier source) describes limited enforcement resources.

Claims (1):

  • Commentary characterises Law 09-08 as championing fair and lawful data processing while facing ambiguous definitions and limited enforcement resources.

Collective Redress And Class ActionsRed

No sourced collective-redress/class-action mechanism found; searched 'Morocco data protection class action' without result.

Private Right Of ActionRed

No sourced private right of action for data subjects found.

Recent Developments 180DAmber

Most recent (within ~180 days of run date) reported CNDP regulatory activity is the May 2026 genomic-data recommendations.

Claims (1):

  • In May 2026, CNDP presented recommendations on the processing of genomic data, representing the most recently reported CNDP regulatory guidance activity within the evaluation window.
Category narrative104 words

The Morocco-EU gap analysis identified limits on the powers granted to CNDP as a divergence from the GDPR enforcement framework. CNDP nonetheless reached a January 2019 agreement with Morocco's Public Ministry establishing a case-tracking system and a dedicated prosecution unit for CNDP-referred cases, and was among 12 authorities that signed an August 2023 joint statement to major social-media companies. Commentary characterises the regime as facing limited enforcement resources. No sourced evidence was found on collective-redress/class-action mechanisms or a private right of action for data subjects; searched 'Morocco data protection class action', 'CNDP private right of action court', and 'CNDP budget headcount' without confirmed results.

Periodic update · new data 2026-09-28

Enforcement & Redress

Morocco's data-protection enforcement posture is reported to be tightening this cycle. Per Chambers and Partners' practice-guide commentary, over the last several months the CNDP has started issuing warnings to major data controllers and has initiated investigations into potential violations by controllers processing significant volumes of personal data. This is understood to represent a shift from what has historically been a largely dormant sanctioning environment under Law 09-08 toward a more active enforcement posture, though the underlying statute itself has not been amended and the shift is one of enforcement practice rather than legal change.

The statutory sanctions ceiling behind this activity has not changed: non-compliance with Law 09-08 remains subject to a fine ranging from MAD 10,000 to MAD 600,000 and, or imprisonment of between three months and four years. The same source reports that the CNDP typically sends a warning before pursuing such sanctions, which is consistent with the warnings-first pattern described for the current wave of major-controller investigations; whether any of the current investigations will progress to a formal fine or referral is not yet established in the evidence available this cycle.

Running alongside this enforcement tightening, discussion continues over GDPR-alignment reforms to Law 09-08, which would introduce a statutory breach-notification deadline, formal data protection impact assessments, enhanced subject rights and an accountability-based compliance model closer to the EU framework. As of this cycle, no formal amending legislation has been enacted, and the existing statute's structural gaps, most notably the absence of any fixed breach-notification deadline, persist. Industry practice recommends notifying the CNDP within less than 72 hours of a breach and informing affected individuals where risk is high, but this is a non-binding recommendation rather than a statutory requirement, and controllers should not treat it as equivalent to a legal deadline.

The combination of an intensifying enforcement posture and an unreformed, GDPR-gap-carrying statute is the defining tension in Morocco's data-protection environment this cycle: enforcement risk is rising in practice even though the legal framework generating the exposure has not itself been modernised to match.

Outlook

The principal item to watch is whether the CNDP's current wave of warnings against major and high-volume data controllers converts into formal sanctions, which would be the first visible test of the statutory fine and imprisonment ceiling under this more active enforcement posture. A secondary item is whether the discussed GDPR-alignment reforms, covering breach notification, DPIAs and accountability obligations, progress from discussion to a formal legislative proposal; no confirmed timeline exists for either development in the evidence available this cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedIAPP — The Morocco-EU gap analysis identified limits on the powers granted to CNDP as an area of divergence from the GDPR's enforcement framework for supervisory authorities.observed
  2. ConfirmedDataGuidance — CNDP and Morocco's Public Ministry agreed in January 2019 on a collaborative roadmap including a case-tracking system and a dedicated prosecution unit for data-protection cases referred by CNDP.observed
  3. ConfirmedOffice of the Privacy Commissioner of Canada — CNDP was among 12 data protection authorities from six continents that signed a joint statement addressed to major social media companies in August 2023.observed
  4. ProbableDataGuidance — In May 2026, CNDP presented recommendations on the processing of genomic data, representing the most recently reported CNDP regulatory guidance activity within the evaluation window.observed
  5. UncertainIAPP — Commentary characterises Law 09-08 as championing fair and lawful data processing while facing ambiguous definitions and limited enforcement resources.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct5.88
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Morocco
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 26 claim(s) (26 category placement(s)), 22 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (15 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 33-34Controller/Processor Dutiesbreach notification
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

Coverage relies predominantly on T3 trade-press secondary reporting (IAPP, DataGuidance) plus one T2 official government issue-sheet (OPC Canada) and one T4 opinion piece. No T1 primary-text access to Law 09-08 or CNDP official guidance/decisions was obtained via search in this run; all claims describing the law's content are derived from a 2018 Morocco-EU gap-analysis study reported by IAPP. Modules with strongest evidence: regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, enforcement_and_redress (partial). Modules with materially thin or absent evidence: controller_processor_duties (DPO/ROPA/retention gaps unconfirmed), sectoral_watch (only health/genomic touched), adtech_and_commercial_privacy (no findings), algorithmic_biometric_and_surveillance_governance (mostly gaps), children_and_vulnerable_groups (only awareness initiative).

Unresolved questions (6):

  • Has Law 09-08 been formally amended since 2009 despite repeated CNDP reform announcements (2018 gap analysis, 2020 COVID-era plans)?
  • What is the current (2026) status of Morocco's pending EU adequacy request?
  • Does Law 09-08 or subsequent CNDP decisions establish a DPO appointment threshold, ROPA obligation, or data retention limits?
  • Has Morocco signed or ratified the African Union Malabo Convention on Cyber Security and Personal Data Protection?
  • What are the exact procedural registration/authorization categories (declaration vs. prior authorization) under the CNDP national register?
  • Are there sector-specific overlays (banking, telecoms, employment, insurance, education, credit) that displace or supplement Law 09-08?

Escalate to primary-source review: yes