Data Protection Atlas

Morocco

Tier 3 Comprehensive law Africa

Principal framework: Law 09-08 on Personal Data Protection (2009). Regulator: CNDP. Law 09-08 (2009) follows the 1995 EU Directive model of prior declarations and authorisations; a GDPR-style overhaul has been in preparation for several years.

At a glance

Principal law
Loi n° 09-08 (2009)
Regulator
Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)
Breach notification
No general statutory deadline; CNDP notification practice
Maximum penalty
Fines to MAD 300,000 plus criminal sanctions on referral
DPO required
Not mandatory; CNDP declarations and authorisations required instead
Digital consent age
Parental consent for minors
Extraterritorial reach
Controllers established in Morocco or using means there

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
MA

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

No instrument profiled yet.

Sources

Never independently verified — seeded from the prototype.