Personal Data Protection in Morocco: What Law 09-08 Requires of Businesses (Obligations and CNDP Sanctions)

Sales CRM, online HR platforms, recruitment tools, e-mail marketing campaigns, employee video surveillance, cloud hosting abroad: nearly every Moroccan company, whatever its size, now collects and processes personal data belonging to its customers, prospects and employees. Yet many are unaware that this processing has been regulated since 2009 by a dedicated statute: Law No. 09-08 on the protection of individuals with regard to the processing of personal data. Less publicized than the European GDPR, this law is nonetheless fully applicable and backed by real criminal and financial sanctions, enforced by the National Commission for the Control of Personal Data Protection (CNDP). This article reviews the obligations placed on businesses and the risks they face in case of non-compliance.

The legal framework: Law 09-08 and its implementing decree

Law No. 09-08 was enacted by Dahir No. 1-09-15 of 22 Safar 1430 (18 February 2009) and published in Official Gazette (Bulletin Officiel) No. 5714 of 5 March 2009. Its implementing decree, Decree No. 2-09-165, sets out the practical procedures, in particular the forms and filing process with the CNDP, the independent administrative authority created by the same law to enforce it.

Article 1 of the law defines personal data as any information, of whatever nature (including sound and image), relating to an identified or identifiable natural person. “Processing” covers any operation or set of operations applied to such data: collection, recording, storage, consultation, disclosure or deletion. The “controller” is the natural or legal person who determines the purposes and means of the processing — in practice, the company itself, not its IT service provider. The law also singles out a category of “sensitive data” (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health data), subject to a stricter regime.

Under Article 2, the law applies to any automated or non-automated processing carried out by a controller established in Morocco, or one that uses processing means located on Moroccan territory, even if its head office is abroad — which includes, for instance, a foreign company using a call centre or subcontractor based in Morocco.

Prior declaration or authorisation: a formality too often overlooked

Before implementing any processing of personal data, a company must, in principle, complete a prior formality with the CNDP, the nature of which depends on the type of data involved (Article 12 et seq.):

A simple declaration is sufficient for most routine processing (payroll management, customer files, accounting, standard recruitment). The CNDP then issues a receipt, in principle within 24 hours, allowing the processing to begin.

Prior authorisation from the CNDP is, however, mandatory for the most sensitive processing: processing of sensitive data within the meaning of Article 1 (Article 21), processing involving the national identity card number, data relating to offences, convictions or security measures, interconnection of files pursuing different purposes, or reuse of data collected for purposes other than those originally declared.

In practice, many Moroccan companies have never completed these formalities, often out of unfamiliarity with the law rather than deliberate choice. Yet the absence of a declaration or authorisation is itself an offence, regardless of any actual misuse of the data.

Rights granted to data subjects

Law 09-08 grants several rights to the individuals whose data is processed (customers, employees, prospects), which the controller must be able to honour:

The right to information (Article 5): the individual must be informed, clearly and unambiguously, of the identity of the controller, the purposes pursued, whether answers are mandatory or optional, the recipients of the data, and the existence of a right of access and rectification — typically through a notice on collection forms (website, contract, recruitment form).

The right of access (Article 7): any individual may obtain confirmation that processing concerning them exists and obtain a copy in an intelligible form, free of charge and within a reasonable time.

The right to rectification (Article 8): inaccurate, incomplete or ambiguous data must be corrected, completed or deleted free of charge, in principle within ten clear days, failing which the Commission may be approached.

The right to object (Article 9) and the regulation of direct marketing (Article 10): any individual may object, on legitimate grounds, to processing, and commercial prospecting by electronic means, telephone or fax is in principle subject to prior consent, except where the contact details were obtained directly from the customer in connection with a prior sale or service.

Transfers of data abroad: a point of caution for companies using the cloud

Many Moroccan companies now host their data (payroll, CRM, e-mail, HR tools) on cloud platforms whose servers are located outside Morocco. This seemingly innocuous practice is in fact subject to the specific regime governing international data transfers under Articles 43 and 44 of the law.

The principle set out in Article 43 is that the transfer of personal data to a foreign country is only possible if that state ensures a sufficient level of protection for individuals’ privacy — the CNDP maintains a list of states considered adequate for this purpose. Failing that, Article 44 provides for exceptions that nonetheless permit the transfer: the data subject’s express consent, protection of their life or the public interest, performance of a contract or pre-contractual measures, necessity for the establishment, exercise or defence of a legal claim, or authorisation by the Commission based on contractual clauses offering sufficient guarantees (in practice, clauses modelled on the European standard contractual clauses).

A company that migrates its HR management or customer relationship data to a foreign cloud provider without checking this point is therefore, in theory, exposed to the same sanctions as an undeclared data transfer.

Sanctions for non-compliance

Law 09-08 carries an enforcement arsenal that many business leaders underestimate, combining fines and prison sentences, with legal entities facing doubled penalties (Article 64) and confiscation of equipment or closure of the establishment in cases of serious breach. In case of repeat offences, all applicable sanctions are doubled (Article 65).

Offence Legal basis Main sanction
Undeclared processing, or processing continued after authorisation is withdrawn Art. 52 Fine of MAD 10,000 to 100,000
Refusal to honour a request for access, rectification or objection Art. 53 Fine of MAD 20,000 to 200,000 (per offence)
Unfair or unlawful collection or processing Art. 54 3 months to 1 year imprisonment and/or MAD 20,000 to 200,000
Retention of data beyond the authorised period Art. 55 3 months to 1 year imprisonment and/or MAD 20,000 to 200,000
Processing without the data subject’s consent Art. 56 3 months to 1 year imprisonment and/or MAD 20,000 to 200,000
Processing sensitive data without express consent Art. 57 3 months to 1 year imprisonment and/or MAD 50,000 to 300,000
Failure to implement adequate security measures Art. 58 3 months to 1 year imprisonment and/or MAD 20,000 to 200,000
Non-compliant international data transfer Art. 60 3 months to 1 year imprisonment and/or MAD 20,000 to 200,000
Obstruction of CNDP oversight Art. 62 3 to 6 months imprisonment and/or MAD 10,000 to 50,000
Refusal to implement a Commission decision Art. 63 3 months to 1 year imprisonment and/or MAD 10,000 to 100,000

Practical points of attention for businesses

  • Map all existing personal data processing activities (customers, prospects, employees, candidates, video surveillance) and check, for each, whether it has been declared or, where applicable, authorised by the CNDP.
  • Update the information notices on the company website, collection forms, employment contracts and commercial agreements, in line with Article 5.
  • Review contracts with technical subcontractors (hosting providers, HR or CRM software vendors, marketing agencies) and include confidentiality and security clauses compliant with Article 23.
  • Identify data flows abroad (cloud hosting, SaaS tools, international group) and secure their legal basis under Articles 43 and 44.
  • Appoint an internal point of contact responsible for handling requests to exercise rights (access, rectification, objection) and meeting the legal response deadlines.
  • Frame electronic or telephone marketing campaigns with a consent-collection mechanism compliant with Article 10.
  • Prepare for a possible CNDP inspection by maintaining an internal record of processing activities, declarations filed and security measures implemented.

Conclusion

Law 09-08 is not a recent statute, but its application remains, in practice, far from complete at many Moroccan companies, which often discover their obligations during an inspection, a dispute, or due diligence in connection with a merger or acquisition. At a time when data has become a strategic asset and digital tools (cloud, CRM, artificial intelligence) are multiplying data flows, proactive compliance is both a legal obligation and a mark of seriousness towards customers, employees and partners.

This article provides a general overview and does not constitute legal advice. For a compliance audit of your personal data processing or assistance with your filings before the CNDP, Westfield law firm is at your disposal.

Leave a Reply

Your email address will not be published. Required fields are marked *