Law / Morocco

Morocco

9 of 12 named instruments researched to a stage, across four of the six areas of law we track: 9 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (238 words)

Morocco's comprehensive data-protection statute is Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, promulgated by Dahir No. 1-09-15 of 22 safar 1430 (18 February 2009) and enforced by the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).

The law binds any physical or legal person, public or private, whose data controller is established in Morocco or who uses processing means located there, and it conditions processing on the data subject's consent or another enumerated ground, requires a prior declaration or CNDP authorization before most processing begins, arms the data subject with information, access, rectification and objection rights, limits automated decision-making based solely on profiling, restricts cross-border transfer to states the CNDP finds adequate, and backs these duties with a graduated schedule of fines and, for several offences, imprisonment.

Its sensitive-data category (Article 1(3)) reaches racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and health data including genetic data; it does not name biometric identifiers such as a voiceprint or faceprint as a sensitive or heightened category, so a service processing a biometric identifier that is not otherwise tied to one of those named categories falls under the law's ordinary consent and declaration duties rather than its heightened prior-authorization regime for sensitive data.

The law states no duty to notify the CNDP or an affected person of a personal data breach.

Comprehensive regime

Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data

Loi n° 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel promulguée par le Dahir n° 1-09-15 du 22 safar 1430 (18 février 2009), arts. 1-4, 12-20, 23, 25-26, 45-48 (dispositions générales, déclaration et sécurité)Text of Law No. 09-08 (French, consolidated)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 25, 2023. Publisher's page: https://www.cndp.ma/wp-content/uploads/2023/11/Loi-09-08-Fr.pdf

In force. Binds public and private bodies.

What this law does

Article 2 applies the law to automated and manual processing of personal data by a physical or legal person, public or private, whose controller is established in Morocco or who uses processing means located there, and Article 2(3) requires a controller established abroad who uses Moroccan processing means to notify the CNDP of a Morocco-based representative who takes on the controller's rights and obligations under the law.

Article 3 requires personal data to be processed fairly and lawfully, collected for determined, explicit and legitimate purposes, kept adequate, relevant and not excessive, accurate and up to date, and retained in identifiable form no longer than those purposes require.

Article 4 requires the data subject's unambiguous consent before processing, unless the processing falls under Article 4's enumerated exceptions (a legal obligation, contract performance, vital interest, a public-interest mission, or the controller's legitimate interest).

Articles 12(2) and 13-20 require processing that is not subject to prior authorization to be the subject of a prior declaration to the CNDP, which issues a receipt within 24 hours, and require the controller to notify the CNDP of any change to the declared particulars.

Article 23 requires the controller to implement technical and organizational measures appropriate to the risk, to bind any processor to equivalent security guarantees, and to record the terms of that arrangement in writing, and Articles 25-26 hold anyone with authorized access to personal data, including a processor, to professional secrecy even after they stop performing that role.

Articles 45-48 establish a national register of declared and authorized processing, maintained by the CNDP and open to the public, and require a controller exempted from declaration because its file is a public register to still make its identity and the processing's particulars known on request.

What it requires

Cross border transfer

Law No. 09-08, transfer of data to a foreign country

Loi n° 09-08, arts. 43-44 (transfert de données vers un pays étranger)Text of Law No. 09-08 (French, consolidated)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 25, 2023. Publisher's page: https://www.cndp.ma/wp-content/uploads/2023/11/Loi-09-08-Fr.pdf

In force. Binds public and private bodies.

What this law does

Article 43 bars a controller from transferring personal data to a foreign state unless that state ensures a sufficient level of protection for privacy and fundamental rights and freedoms with regard to the processing, judged by the state's rules, its security measures, and the processing's purpose, duration, origin and destination, and the CNDP maintains the list of states meeting that standard.

Article 44 lets a controller transfer to a state that does not meet it where the data subject has expressly consented, or without that consent where the transfer is necessary to save the person's life, to preserve the public interest, to establish, exercise or defend a legal claim, to perform a contract with the data subject or precontractual measures at their request, to perform a contract concluded in the data subject's interest between the controller and a third party, to carry out international judicial assistance, or to prevent, diagnose or treat a medical condition; it also permits a transfer under a bilateral or multilateral agreement Morocco is party to, or on the CNDP's own express and reasoned authorization where contractual clauses or internal rules ensure a sufficient level of protection.

What it requires

Data subject rights

Law No. 09-08, rights of the data subject

Loi n° 09-08, arts. 5-11 (droits de la personne concernée)Text of Law No. 09-08 (French, consolidated)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 25, 2023. Publisher's page: https://www.cndp.ma/wp-content/uploads/2023/11/Loi-09-08-Fr.pdf

In force. Binds public and private bodies.

What this law does

Article 5 requires a controller collecting data directly from a data subject to tell them, expressly, precisely and unambiguously, the controller's identity, the purposes of the processing and, where fair processing requires it, the recipients, whether a response is mandatory and the consequences of not responding, the existence of access and rectification rights, and the receipt or authorization the processing rests on; where the data were not collected from the data subject, Article 5(3) requires that information no later than the first disclosure to a third party.

Article 6 exempts national-defense and internal or external state-security processing, cases where informing the data subject proves impossible for statistical, historical or scientific processing, processing a law expressly directs to be recorded or disclosed, and processing for exclusively journalistic, artistic or literary purposes.

Article 7 gives the data subject the right to obtain, at reasonable intervals, without delay and free of charge, confirmation of processing, the data in intelligible form, and the logic underlying an automated treatment of them, letting the controller ask the CNDP for more time or oppose manifestly abusive requests.

Article 8 gives a right to correct, update, erase or block noncompliant data within ten clear days, free of charge, and to have the correction passed on to any third party the data were disclosed to, escalating to the CNDP on refusal or non-response. Article 9 gives a right to object on legitimate grounds, and an unconditional and free right to object to use of the data for prospecting, including commercial prospecting.

Article 10 bars direct marketing by automated call, fax or electronic mail to a person who has not given prior consent, with a narrow exception for email marketing of similar products to a controller's own existing customers, conditioned on an easy, free opt-out being offered at collection and with every message.

Article 11 bars a judicial decision, and any other decision producing legal effects on a person, from resting solely on automated processing meant to define their profile or evaluate an aspect of their personality, except a decision taken in forming or performing a contract where the person could comment, or one that grants the person's own request.

What it requires

Enforcement supervision

Law No. 09-08, the CNDP and sanctions

Loi n° 09-08, arts. 27-42, 51-66 (Commission nationale, sanctions)Text of Law No. 09-08 (French, consolidated)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 25, 2023. Publisher's page: https://www.cndp.ma/wp-content/uploads/2023/11/Loi-09-08-Fr.pdf

In force. Binds public and private bodies.

What this law does

Article 27 establishes the CNDP under the Prime Minister to implement and enforce the law, advise the government and parliament on processing-related bills and regulations, and receive declarations, representative notifications and complaints.

Article 28 gives it power to authorize extended retention and response delays, order corrections, issue the Article 12 and Article 21 authorizations, set the adequate-states list, authorize transfers, run the national register, grant security-measure exemptions, escalate a declared processing to authorization, and withdraw a receipt or authorization.

Articles 30-31 give the CNDP's commissioned agents investigative and enforcement powers, including access to processing sites and data and the power to order blocking, erasure, destruction or a halt to processing, exercised under a disciplinary procedure that guarantees the rights of the defense.

Articles 32-42 set the CNDP's composition (a president and six members, all royally appointed, serving five-year terms renewable once), its meeting and voting rules, member incompatibilities and recusal duties, professional secrecy for its members and staff, and its secretariat and committee structure. Article 51 lets the CNDP withdraw a declaration receipt or an authorization, without delay, where the processing it covers threatens public security or order or offends morality.

Articles 52-63 set a graduated penalty ladder: undeclared or unauthorized processing draws a fine of 10,000 to 100,000 dirhams only (Article 52); refusing an access, rectification or objection request draws a fine of 20,000 to 200,000 dirhams per infraction (Article 53); unlawful collection, off-purpose processing, over-retention, processing without the required consent, inadequate security measures, disregarding a legitimate or marketing objection, and an unlawful cross-border transfer each draw imprisonment of three months to one year and a fine of 20,000 to 200,000 dirhams (Articles 54-56, 58-60); processing sensitive data or offense and conviction data without the required consent or authorization draws imprisonment of three months to one year and a fine of 50,000 to 300,000 dirhams, the statute's highest tier (Article 57); obstructing CNDP control draws imprisonment of three to six months and a fine of 10,000 to 50,000 dirhams (Article 62); and refusing to comply with a CNDP decision draws imprisonment of three months to one year and a fine of 10,000 to 100,000 dirhams (Article 63).

Article 52 states these criminal sanctions without prejudice to the civil liability of anyone whose fault causes damage, preserving a data subject's ordinary civil claim for compensation. Article 64 doubles fines for a legal person and adds asset confiscation or closure of the establishment as available sanctions, and Article 65 doubles all sanctions on recidivism within a year of a final conviction.

Article 66 lets specially commissioned and sworn CNDP agents, alongside judicial police officers, investigate and record offenses by official report, forwarded to the public prosecutor within five days.

What it requires

Sensitive categories

Law No. 09-08, sensitive personal data and offense records

Loi n° 09-08, arts. 12(1), 21-22, 24, 49-50 (données sensibles et catégories protégées)Text of Law No. 09-08 (French, consolidated)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 25, 2023. Publisher's page: https://www.cndp.ma/wp-content/uploads/2023/11/Loi-09-08-Fr.pdf

In force. Binds public and private bodies.

What this law does

Article 12(1) makes prior CNDP authorization, rather than a mere declaration, the default for processing sensitive data, for using data outside the purpose it was collected for, for genetic data outside medical care, for data on offenses, convictions or security measures, for a national identity card number, and for interconnecting files serving different public or private purposes.

Article 21 conditions that authorization on the data subject's express consent, a legal or statutory duty of the controller, or the Commission's own finding that the processing protects a vital interest, concerns data the data subject has manifestly made public, or is necessary to a legal claim.

Article 22 lets a controller declare rather than seek authorization for health data processed solely for preventive medicine, diagnosis, care or health-service management by a practitioner or another person equally bound by professional secrecy, or to select beneficiaries of a right, benefit or contract they are not otherwise excluded from.

Article 24 requires a controller of sensitive or health data to additionally control entry to the processing facility, control who can read, copy, modify or remove the data media, control unauthorized input, use, access and transmission, and be able to show after the fact what data was input, when and by whom.

Articles 49-50 restrict processing personal data on offenses, convictions or security measures to courts, public authorities and legally competent public bodies, and to auxiliaries of justice acting within the strict needs of their legal mission. The law's sensitive-data definition (Article 1(3)) does not include a biometric, voiceprint or faceprint identifier.

What it requires

Scraping law1 instrument, 1 in force

Research summary (114 words)

Morocco's copyright statute, Law No. 2-00 on Copyright and Related Rights, promulgated in 2000 and amended by Law No. 34-05 (2006) and Law No. 79-12 (2014), is the source reaching a scraper's collection and reproduction of a database or other protected work; it protects a database as a compilation rather than through a separate sui generis right, and its enumerated exceptions expressly withhold the private-use exception from digital-form database reproduction, with no text-and-data-mining exception or machine-readable opt-out of any kind.

Morocco's legacy corpus separately records a criminal computer-misuse amendment to the Penal Code, Law No. 07-03, supplementing the Penal Code and promulgated in November 2003. Not read, so its provisions are not described here.

Cybersecurity law2 instruments, 2 in force

Research summary (789 words)

Morocco's principal cybersecurity statute is Loi n° 05-20 relative à la cybersécurité, promulgated by Dahir n° 1-20-69 of 4 hija 1441 (25 July 2020) and published in Bulletin Officiel n° 6906 of 16 hija 1441 (6 August 2020).

Article 1 sets three bound-party classes: an 'entité' (a state administration, territorial collectivity, public establishment or enterprise, or another public-law legal person), an infrastructure d'importance vitale (a designated critical-infrastructure operator, CII), and an 'opérateur' grouping a public telecommunications network operator, an Internet access provider, a cybersecurity service provider, a digital service provider, and an Internet platform publisher.

The entité duties (Chapter II, Section 1, Articles 3 to 13) bind a government body rather than a private-sector duty-bearer, so they sit outside this topic's scope entirely.

The CII duties (Chapter II, Section 2, Articles 14 to 25) bind a government-designated critical infrastructure operator, an activity this corpus's vocabulary cannot express, so that regime is recorded here rather than raised against a declared activity, the same treatment this profile gives Singapore's and Japan's designated critical-infrastructure operators.

Within the opérateur class, a public telecommunications network operator, an Internet access provider, and a cybersecurity service provider carry the same Chapter II, Section 3 duties but likewise reach no declared activity in this corpus's vocabulary, so they too are named here without being flagged.

A digital service provider (defined in Article 2 to include an online sale or service-contract platform, an online search engine, and a datacenter or cloud-computing host) and an Internet platform publisher are the two opérateur sub-categories this corpus can express, through the operates_social_platform activity, the same proxy this profile's own European Union row uses for the equivalent NIS2 Annex II categories.

Chapter II, Section 3 binds these two sub-categories, together with the three that reach no activity, to retain technical incident-identification data for one year (Article 26), take authority-directed protective measures for their clients (Article 29), and, for a digital service provider specifically, manage its own information-system risk to guarantee service continuity (Article 32) subject to an authority-ordered compliance audit (Article 34); these four articles are filed here as a sector_security_regimes instrument.

The same operators must notify a client of a vulnerability or breach (Article 27), notify the national authority without delay of an event affecting a client's systems (Article 30), and, for a digital service provider, declare its own significant-impact incident to the national authority as soon as it becomes aware of it (Article 33); these three articles are filed here as a vulnerability_and_incident_reporting instrument.

Article 53 defers the law's own commencement to the Bulletin Officiel publication of the texts taken for its application; Décret n° 2-21-406 of 4 hija 1442 (15 July 2021), a text DGSSI's own site lists as taken for the application of Loi n° 05-20, is the earliest confirmed implementing text, and DGSSI has continued issuing implementing and qualification texts under the law through 2025 (most recently an Arrêté of 1 August 2025 on cloud service provider qualification), so the regime is treated here as in effect, though a day-precise commencement date for every provision is not confirmed and that decree's own text was not read past its title.

Chapter V (Articles 48 to 52) makes a breach of Article 26, 30, 32, 33 or 34 an offence carrying a fine of 100,000 to 200,000 dirhams, doubled on recidivism within four years; Article 27's client-notification duty and Article 29's protective-measures duty are not among the provisions Chapter V lists as carrying a fine.

The Direction Générale de la Sécurité des Systèmes d'Information (DGSSI) describes its own role, on its own published site, as drafting the legislative and regulatory texts relating to cybersecurity and issuing the authorizations and approvals the law contemplates, and operates as the national cybersecurity authority (autorité nationale) Article 1 says is designated by regulation, alongside the Cybersecurity Strategy Committee and the major-crisis management committee the law itself creates (Articles 35 and 36).

No product-security requirement binding a manufacturer before a connected device or software product reaches the Moroccan market, and no baseline reasonable-security statute reaching a business regardless of sector, is confirmed to exist; Article 32's risk-management duty is gated to a digital service provider specifically rather than to any business, so it is filed as a sector regime rather than a baseline statute.

No cybersecurity circular issued by Bank Al-Maghrib or by the Agence Nationale de Réglementation des Télécommunications (ANRT) reaching a software or platform provider is confirmed to exist; a public telecommunications network operator's or Internet access provider's cyber duties run through Loi n° 05-20 itself rather than through a distinct sector-regulator circular.

Morocco's data-protection statute, Loi n° 09-08, already this jurisdiction's privacy-topic instrument, is a separate, general regime, and any security-of-processing duty it carries stays there rather than being restated here.

Sector security regimes

Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties

Loi n° 05-20 relative à la cybersécurité Chapitre II, Section 3, Arts. 26, 29, 32 et 34, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020)Text of Loi n° 05-20 relative à la cybersécurité

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.dgssi.gov.ma/sites/default/files/legislative/brochure/2023-03/loi%2005-20.pdf

In force. Binds private bodies.

What this law does

Chapter II, Section 3 of Loi n° 05-20 relative à la cybersécurité binds a 'prestataire de services numériques' (digital service provider), defined in Article 2 to include an operator of an online sale or service-contract platform, an online search engine, or a datacenter or cloud-computing host, and an 'éditeur de plateformes Internet' (Internet platform publisher), together with a public telecommunications network operator, an Internet access provider and a cybersecurity service provider, all five grouped by Article 1 as an 'opérateur'.

Article 26 requires an opérateur to comply with the national cybersecurity authority's directives on retaining, for one year from generation, the technical data needed to identify a cybersecurity incident, including connection data, system logs, and the security-event traces generated by its operating systems, applications and security products.

Article 29 requires an opérateur to take the protective measures the national authority directs to prevent and neutralize the effects of a threat or breach affecting its clients' information systems.

Article 32 requires a digital service provider specifically to identify the risks threatening the security of its own networks and information systems, and to take the technical and organizational measures needed to manage those risks, avoid incidents, and minimize their impact, so as to guarantee the continuity of its services.

Article 34 lets the national authority, on being informed that a digital service provider does not meet an obligation the law imposes, subject that provider to a compliance audit at its own cost, and order its directors to come into compliance within a deadline the authority sets.

A violation of Article 26 or of Article 32 or 34 draws a fine of 100,000 to 200,000 dirhams under Article 50, doubled on recidivism within four years under Article 52; Article 29's protective-measures duty is not among the provisions Article 50 lists.

The Direction Générale de la Sécurité des Systèmes d'Information (DGSSI) describes its own regulatory role as drafting the legislative and regulatory texts relating to cybersecurity and issuing the authorizations and approvals the law contemplates, and operates as the national cybersecurity authority (autorité nationale) Article 1 says is designated by regulation.

What it requires

Vulnerability and incident reporting

Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Incident and Vulnerability Notification Duties

Loi n° 05-20 relative à la cybersécurité Chapitre II, Section 3, Arts. 27, 30 et 33, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020)Text of Loi n° 05-20 relative à la cybersécurité

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.dgssi.gov.ma/sites/default/files/legislative/brochure/2023-03/loi%2005-20.pdf

In force. Binds private bodies.

What this law does

Chapter II, Section 3 of Loi n° 05-20 relative à la cybersécurité also binds the same opérateur class, a public telecommunications network operator, an Internet access provider, a cybersecurity service provider, a digital service provider, and an Internet platform publisher, to three notification duties with their own clocks. Article 27 requires an opérateur to inform its clients of a vulnerability in its information systems, or of a breach that could affect them.

Article 30 requires an opérateur, on detecting an event that could affect the security of a client's information systems, to inform the national cybersecurity authority of it without delay.

Article 33 requires a digital service provider specifically, as soon as it becomes aware of an incident affecting the networks or information systems its service needs, to declare the incident to the national authority where the information available to it shows the incident has a significant impact on providing that service.

A violation of Article 30 or 33 draws the same fine of 100,000 to 200,000 dirhams under Article 50 that Article 8's parallel duty on an entité draws, doubled on recidivism within four years under Article 52; Article 27's client-notification duty is not among the provisions Article 50 lists.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (100 words)

Morocco's Law No. 2-00 on Copyright and Related Rights carries two free-use exceptions bearing on the reproduction of published material: a general quotation exception (Article 14) and a press-specific exception for economic, political, or religious articles (Article 19(a)), each conditioned on citing the source and the author's name. Neither exception is a dedicated news-aggregation privilege, and the text does not address a systematic aggregator's reproduction of headlines and snippets.

Other aggregation-law dimensions, including a press-publisher neighbouring right, a compelled platform-to-publisher bargaining regime, a hot-news doctrine, and case law on hyperlinking or framing: not read, so they are not described here.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.