EU framework governing the collection, processing, and movement of personal data.
Last updated — August 22, 2026
Any organization established in the European Union that processes personal data, as well as organizations outside the EU that target or monitor individuals located in the EU (offering goods/services, tracking behavior).
A documented legal basis for each processing activity, a records of processing register, security measures proportionate to risk, transparent information to data subjects, mechanisms for exercising rights (access, rectification, erasure, portability), a Data Protection Impact Assessment (DPIA) for high-risk processing, safeguards for transfers outside the EU, and notification of data breaches to the competent supervisory authority and, where applicable, to affected individuals.
Deadlines
A data breach must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
Sanctions
Administrative fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher, depending on the nature of the infringement.
Map processing activities and personal data flows
Identify legal bases and update the records of processing register
Conduct a DPIA for high-risk processing activities
Implement technical and organizational security measures
Formalize procedures for data subject rights requests and breach notification
| Framework | Covered |
|---|---|
| loi-09-08-cndp | ✓ |
| nis2 | ✓ |
Get the checklist by email.
Yes, if it processes data of individuals located in the EU in connection with offering goods or services, or monitoring their behavior, regardless of where the company is established.
Both frameworks share similar principles (consent, purpose limitation, security) but fall under different authorities and scopes; an organization active in both Morocco and Europe generally needs to satisfy both.
It is mandatory in specific cases defined by the regulation (public authority, large-scale monitoring, large-scale processing of sensitive data); outside those cases, appointing one remains a sound governance practice.
A Data Protection Impact Assessment describes the processing, assesses its necessity and proportionality, identifies risks to data subjects, and defines measures to mitigate them.