Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Loi n° 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel promulguée par le Dahir n° 1-09-15 du 22 safar 1430 (18 février 2009), arts. 1-4, 12-20, 23, 25-26, 45-48 (dispositions générales, déclaration et sécurité)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Process personal data only where it is collected fairly and lawfully for determined, explicit and legitimate purposes, and do not process it later in a way incompatible with those purposes.
- Keep personal data adequate, relevant, accurate, and not excessive for those purposes, and do not retain it in identifiable form longer than the purposes require.
- Obtain the data subject's unambiguous consent before processing their personal data, unless a legal obligation, contract performance, vital interest, public interest mission, or legitimate interest ground applies.
- File a prior declaration with the CNDP before implementing an automated processing operation, or a set of related automated operations, unless the processing instead requires the CNDP's prior authorization.
- If you are established outside Morocco but use processing means located there, notify the CNDP of the identity of a Morocco based representative who takes on your rights and obligations under the law.
- Implement technical and organizational measures appropriate to the risk and the state of the art, protecting personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure, and unauthorized access, including where the processing involves network transmission.
- Bind any processor you use to security guarantees equivalent to your own by contract, and hold anyone with authorized access to personal data, including after they leave that role, to professional secrecy.
- Notify the CNDP without delay of any change to a declared processing's particulars or of ending the processing, so its national register of declared and authorized processing stays current.
What it reaches
Obligation class
Consent, Disclosure, Governance, Security, Retention, Licensing
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 2 applies the law to automated and manual processing of personal data by a physical or legal person, public or private, whose controller is established in Morocco or who uses processing means located there, and Article 2(3) requires a controller established abroad who uses Moroccan processing means to notify the CNDP of a Morocco-based representative who takes on the controller's rights and obligations under the law.
Article 3 requires personal data to be processed fairly and lawfully, collected for determined, explicit and legitimate purposes, kept adequate, relevant and not excessive, accurate and up to date, and retained in identifiable form no longer than those purposes require.
Article 4 requires the data subject's unambiguous consent before processing, unless the processing falls under Article 4's enumerated exceptions (a legal obligation, contract performance, vital interest, a public-interest mission, or the controller's legitimate interest).
Articles 12(2) and 13-20 require processing that is not subject to prior authorization to be the subject of a prior declaration to the CNDP, which issues a receipt within 24 hours, and require the controller to notify the CNDP of any change to the declared particulars.
Article 23 requires the controller to implement technical and organizational measures appropriate to the risk, to bind any processor to equivalent security guarantees, and to record the terms of that arrangement in writing, and Articles 25-26 hold anyone with authorized access to personal data, including a processor, to professional secrecy even after they stop performing that role.
Articles 45-48 establish a national register of declared and authorized processing, maintained by the CNDP and open to the public, and require a controller exempted from declaration because its file is a public register to still make its identity and the processing's particulars known on request.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Text of Law No. 09-08 (French, consolidated)
reproduced by the Direction Générale de la Sécurité des Systèmes d'Information (DGSSI) and mirrored by the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP)
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 25, 2023. Publisher's page: https://www.cndp.ma/wp-content/uploads/2023/11/Loi-09-08-Fr.pdfEvery line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.