Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Law 09-08 & CNDP

Morocco's law on the protection of individuals with regard to the processing of personal data, overseen by CNDP.

Last updatedAugust 22, 2026

Who's affected

Any natural or legal person, public or private, that processes personal data within Moroccan territory or by means located in Morocco, with the exception of strictly personal or household processing.

What the framework requires

Law 09-08 requires, among other things, a legal basis for each processing activity, information to data subjects, security measures proportionate to the risk, and, depending on the case, a prior declaration or authorization request filed with CNDP before the processing begins.

Compliance steps

01

Map all personal data processing activities

02

Determine the legal basis for each processing activity

03

Complete the required prior formalities with CNDP (declaration or authorization)

04

Implement appropriate security and information measures

05

Keep the processing register up to date and track data subject rights requests

Common mistakes

  • Failing to distinguish processing subject to simple declaration from processing requiring prior authorization
  • Neglecting to inform data subjects at the point of collection
  • Not keeping an up-to-date processing register

Cross-mapping to other frameworks (UCM)

FrameworkCovered
rgpd

Downloadable resource

Get the checklist by email.

Frequently asked questions

Who is subject to Law 09-08?

Any public or private entity that processes personal data in Morocco or by means located in Morocco, excluding strictly personal or household processing.

What is the role of CNDP?

The National Commission for the Control of the Protection of Personal Data is the authority responsible for receiving prior formalities, controlling the application of Law 09-08, and handling complaints.

Must all personal data processing be declared to CNDP?

No. The applicable regime — simplified declaration, normal declaration, or prior authorization — depends on the nature and sensitivity of the processing concerned.

Is Law 09-08 equivalent to the European GDPR?

Both texts share similar principles (legal basis, information, security), but remain distinct legal frameworks with their own formalities and supervisory authority.

What are the consequences of non-compliance with Law 09-08?

CNDP can initiate control measures, and depending on the severity of the breach, the administrative and criminal sanctions regime provided for by the law may apply.