Since 2009, law 09-08 has governed the processing of personal data in Morocco. For fifteen years the CNDP mostly raised awareness. Since 2025 it inspects, issues formal notices and sanctions, sector by sector. Here is what a small business must actually do, and the mistakes that come up in every inspection.
Key point
- Who is concerned
- The five obligations
- Cloud services and transfers outside Morocco
- The sanctions
Who is concerned
Any company that processes data about individuals living in Morocco: customers, prospects, employees, suppliers, visitors filmed by a camera. Size is irrelevant. A three-person online shop that keeps WhatsApp numbers and delivery addresses is a data controller within the meaning of the law.
The five obligations
- 1Declare every processing operation to the CNDP before starting it. Some routine operations (payroll, accounting) benefit from exemptions under conditions; sensitive data (health, biometrics, beliefs) requires prior authorisation, which takes two to four months to obtain.
- 2Inform people at the point of collection: who is processing, for what purpose, whether an answer is mandatory, who receives the data, and what their rights are.
- 3Honour those rights: access (a copy within 30 days), rectification, objection to marketing, deletion, portability.
- 4Secure the data: restricted access, encryption, traceability, a contract with every processor who touches the data, including your software vendor.
- 5Limit retention: no indefinite storage. Payslips are kept five years after an employee leaves, CCTV one month at most, prospect data according to the purpose.
Cloud services and transfers outside Morocco
Hosting data with a foreign provider is a transfer. It requires CNDP authorisation, except to countries recognised as offering an adequate level of protection, which includes the European Union. It is a question to put to any software vendor: where is my data, and is hosting in Morocco possible for organisations that are required to do so?
The sanctions
| Offence | Fine (legal entity) | Possible sentence |
|---|---|---|
| Undeclared processing | 20,000 to 200,000 MAD | 3 months to 1 year |
| Sensitive data without authorisation | 100,000 to 600,000 MAD | 6 months to 2 years |
| Security failure | 100,000 to 600,000 MAD | 6 months to 2 years |
Beyond the amounts, the CNDP can suspend a processing operation or withdraw an authorisation, which amounts to banning the activity that depends on it. Since 2025 it has run targeted sector campaigns, notably in hospitality, healthcare and online retail.
The mistakes we see most
- Collecting WhatsApp numbers during a sale and then using them for promotions without consent.
- No information notice on the website form, nor on the order form.
- An Excel customer file shared by email, without a password, between salespeople.
- No processing agreement with the IT provider or the software vendor.
- A CNDP declaration made ten years ago and never updated, even though the processing has changed.
What about the GDPR?
If you have customers in the European Union, the European regulation applies on top of law 09-08. A Moroccan reform bill under discussion aims to bring the two frameworks closer (broader legal bases, stronger accountability, higher penalties). Nothing has been adopted to date: law 09-08 remains the applicable text.
Where Cosensible fits in
Our AI charter
Cosensible products are built within law 09-08 and the laws of each country: encrypted data, logged access, identities pseudonymised before any call to a model, a processing annex attached to the subscription terms, export at any time. Our AI charter says what the AI does and does not do.
Discover Our AI charterSources consulted



