Comprehensive regime
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Loi n° 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel promulguée par le Dahir n° 1-09-15 du 22 safar 1430 (18 février 2009), arts. 1-4, 12-20, 23, 25-26, 45-48 (dispositions générales, déclaration et sécurité)Text of Law No. 09-08 (French, consolidated)
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 25, 2023. Publisher's page: https://www.cndp.ma/wp-content/uploads/2023/11/Loi-09-08-Fr.pdfIn force. Binds public and private bodies.
What this law does
Article 2 applies the law to automated and manual processing of personal data by a physical or legal person, public or private, whose controller is established in Morocco or who uses processing means located there, and Article 2(3) requires a controller established abroad who uses Moroccan processing means to notify the CNDP of a Morocco-based representative who takes on the controller's rights and obligations under the law.
Article 3 requires personal data to be processed fairly and lawfully, collected for determined, explicit and legitimate purposes, kept adequate, relevant and not excessive, accurate and up to date, and retained in identifiable form no longer than those purposes require.
Article 4 requires the data subject's unambiguous consent before processing, unless the processing falls under Article 4's enumerated exceptions (a legal obligation, contract performance, vital interest, a public-interest mission, or the controller's legitimate interest).
Articles 12(2) and 13-20 require processing that is not subject to prior authorization to be the subject of a prior declaration to the CNDP, which issues a receipt within 24 hours, and require the controller to notify the CNDP of any change to the declared particulars.
Article 23 requires the controller to implement technical and organizational measures appropriate to the risk, to bind any processor to equivalent security guarantees, and to record the terms of that arrangement in writing, and Articles 25-26 hold anyone with authorized access to personal data, including a processor, to professional secrecy even after they stop performing that role.
Articles 45-48 establish a national register of declared and authorized processing, maintained by the CNDP and open to the public, and require a controller exempted from declaration because its file is a public register to still make its identity and the processing's particulars known on request.
What it requires