The statutory ceiling behind this enforcement activity remains a fine ranging from MAD 10,000 to MAD 600,000 and, or imprisonment of between three months and four years, with the CNDP typically sending a warning before pursuing such sanctions, per the same source. Separately, GDPR-alignment reforms to Law 09-08, covering breach notification, DPIAs, enhanced subject rights and an accountability model, remain under discussion, but as of this cycle no formal amending legislation has been enacted.
Other Developments
Reform discussion continues without enactment. The prospect of bringing Law 09-08 closer to GDPR-style obligations, including a statutory breach-notification deadline, data protection impact assessments and an accountability-based compliance model, is reported as under consideration, but no enacted amendment exists as of this cycle. This means the current statute's gaps, including the absence of any fixed breach-notification deadline, persist unchanged even as enforcement activity around the existing framework intensifies.
Cross-Monitor Connections
The CNDP's enforcement escalation against major and high-volume data controllers is a matter primarily internal to the data-protection domain, but it has bearing on financial-integrity's compliance-technology and controller-accountability readings where the controllers under investigation operate in financial services. It also bears on world-payments' consumer-protection considerations to the extent that high-volume payment-data controllers fall within the CNDP's expanded enforcement attention, though this brief does not itself analyse either domain and links out to those monitors' own coverage rather than colonising it.
Outlook
The principal items to watch are whether the CNDP's warnings against major controllers progress into formal sanctions, which would be the first visible test of the statutory fine and imprisonment ceiling under an active-enforcement rather than dormant posture, and whether the discussed GDPR-alignment reforms to Law 09-08 advance to a formal legislative proposal. Neither has a confirmed timeline in the evidence available this cycle.
Standing brief · as of 25 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Reports indicate that Morocco's data protection authority, the CNDP, intensified its enforcement of Law 09-08 during 2025, though the extent of that intensification rests on a single secondary source. A separate claim circulating in the same reporting wave asserts that a new statute, referred to as "Law 07-26," has been fully implemented and introduces tiered dissuasive fines for data protection breaches. That claim is contested: a more heavily sourced review states that no formal amending legislation has been enacted as of 2026, and the "Law 07-26" claim rests on a single T4 blog source not corroborated elsewhere. Given the conflict between sources, this development is best treated as unverified rather than as a confirmed change to Morocco's penalty regime.
Other Developments
Morocco's core data protection architecture remains structurally stable. The CNDP is the only personal data protection regulator in Morocco, with jurisdiction over all data controllers and processors subject to Law 09-08. Law 09-08 also applies to a foreign-established data controller using automated or non-automated means to process personal data in Moroccan territory, except transit-only processing or processing destined for a country with equivalent data protection legislation. Processing activities must generally be declared in advance to the CNDP unless exempt, dispensed from declaration, or subject to prior authorization.
Law 09-08 places greater emphasis on consent and regulatory filings than the EU GDPR's accountability-based model. Enhanced safeguards apply to sensitive personal data including ethnic or racial origin, political or religious beliefs, trade union membership, health status, and genetic characteristics.
Draft GDPR-alignment amendments would introduce data portability among other GDPR-aligned enhancements to Law 09-08, but as of 2026 no formal amending legislation has been enacted. Separately, draft amendments would also introduce mandatory breach notification, with the same enactment status as of 2026. Law 09-08 does not impose a mandatory Data Protection Officer appointment requirement, unlike the GDPR. Controllers must implement technical and organisational measures to secure personal data against unauthorised access, alteration, and disclosure.
Morocco's international-transfer regime is stricter and more authorization-centric than the GDPR's SCC/BCR framework. The European Commission has not issued an adequacy decision in respect of Morocco, although the CNDP has pursued efforts to demonstrate the adequacy of Morocco's data protection standards.
A single lower-tier source describes a financial-sector overlay in which credit bureaus must respect rules issued by the Governor of Bank Al-Maghrib; breaches or retention beyond a five-year maximum are said to trigger sector-specific sanctions in addition to CNDP fines. This claim rests on a single T4 source and has not been corroborated by higher-tier sources.
The CNDP has not issued specific detailed guidance on cookies or adtech as of 2026, though any future reform of Law 09-08 may address this area.
The CNDP's March 2025 communique on AI and personal data protection states that AI-driven processing of personal data must ensure citizens have effective means of redress. The CNDP is currently preparing a decision on AI and personal data, following a September 2025 partnership agreement with the Ministry of Digital Transition to develop a national platform for responsible AI.
A single lower-tier source describes the CNDP as able to withdraw a company's processing authorization and publish sanctions in the Official Gazette or national newspapers as a name-and-shame measure, in addition to fines; this characterization has not been corroborated elsewhere.
Cross-Monitor Connections
The credit-bureau sectoral overlay under Bank Al-Maghrib rules intersects with financial-sector data governance tracked on the financial-integrity monitor. Readers following related financial-sector developments in Morocco may wish to consult that monitor for further context. No material connection to the crypto monitor was identified this cycle.
Outlook
Morocco's GDPR-alignment reform track, encompassing data portability and mandatory breach notification, has appeared as proposed-only across multiple reporting cycles. This pattern suggests a stalled rather than advancing amendment process. The CNDP's AI-governance activity, by contrast, appears to be building toward a dedicated deliberation on AI and personal data. The contested Law 07-26 claim will require primary-source verification before it can be treated as a confirmed change to Morocco's enforcement and penalty regime.