Morocco
Tier 3 Comprehensive law AfricaPrincipal framework: Law 09-08 on Personal Data Protection (2009). Regulator: CNDP. Law 09-08 (2009) follows the 1995 EU Directive model of prior declarations and authorisations; a GDPR-style overhaul has been in preparation for several years.
At a glance
- Principal law
- Loi n° 09-08 (2009)
- Regulator
- Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)
- Breach notification
- No general statutory deadline; CNDP notification practice
- Maximum penalty
- Fines to MAD 300,000 plus criminal sanctions on referral
- DPO required
- Not mandatory; CNDP declarations and authorisations required instead
- Digital consent age
- Parental consent for minors
- Extraterritorial reach
- Controllers established in Morocco or using means there
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- MA
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- No
- EEA member
- No
Instruments
No instrument profiled yet.
Sources
- Primary Loi n° 09-08 (2009)
Never independently verified — seeded from the prototype.