Law / Morocco

Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Security Duties

Loi n° 05-20 relative à la cybersécurité Chapitre II, Section 3, Arts. 26, 29, 32 et 34, promulguée par le Dahir n° 1-20-69 du 4 hija 1441 (25 juillet 2020), Bulletin Officiel n° 6906 du 16 hija 1441 (6 août 2020)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A sector security regimes rule binding private bodies.

As of 17 September 2026.

What it requires

  • This duty reaches you where you operate an online marketplace or service-contract platform, an online search engine, or a datacenter or cloud-computing hosting service (a prestataire de services numériques under Article 2), or you publish an Internet platform (éditeur de plateformes Internet); Loi n° 05-20 groups you with a public telecommunications network operator, an Internet access provider and a cybersecurity service provider as an opérateur, but those three carry no separate product or platform duty this corpus can express.
  • Comply with the national cybersecurity authority's directives on retaining, for one year from generation, the technical data needed to identify a cybersecurity incident, including connection data, system logs, and the security-event traces your operating systems, applications and security products generate.
  • Take the protective measures the national cybersecurity authority directs to prevent and neutralize the effects of a threat or breach affecting your clients' information systems.
  • If you are a digital service provider, identify the risks threatening the security of your own networks and information systems, and take the technical and organizational measures needed to manage those risks, avoid incidents, and minimize their impact, so as to guarantee the continuity of your services.
  • Expect the national cybersecurity authority to open a compliance audit at your own cost if it is informed you do not meet one of these obligations, and to order your directors, within a deadline it sets, to come into compliance.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Article 50 fixes a fine of 100,000 to 200,000 dirhams for a telecommunications network operator's, Internet access provider's, cybersecurity service provider's, digital service provider's or Internet platform publisher's breach of the Article 26 data-retention duty, and for a digital service provider's failure to take the Article 32 risk-management measures or its obstruction of an Article 34 compliance audit; Article 52 doubles the sanction on recidivism within four years. Article 29's protective-measures duty is not among the provisions Chapter V lists as carrying a fine.

Rule
Fixed only
As of
17 September 2026
Minimum
100,000
Currency
MAD
Fixed cap
200,000

Who enforces it

Enforcement body

The national cybersecurity authority (autorité nationale) Loi n° 05-20 creates; DGSSI (Direction Générale de la Sécurité des Systèmes d'Information) operates in that role per its own published materials.

What it reaches

Obligation class

Retention, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Chapter II, Section 3 of Loi n° 05-20 relative à la cybersécurité binds a 'prestataire de services numériques' (digital service provider), defined in Article 2 to include an operator of an online sale or service-contract platform, an online search engine, or a datacenter or cloud-computing host, and an 'éditeur de plateformes Internet' (Internet platform publisher), together with a public telecommunications network operator, an Internet access provider and a cybersecurity service provider, all five grouped by Article 1 as an 'opérateur'.

Article 26 requires an opérateur to comply with the national cybersecurity authority's directives on retaining, for one year from generation, the technical data needed to identify a cybersecurity incident, including connection data, system logs, and the security-event traces generated by its operating systems, applications and security products.

Article 29 requires an opérateur to take the protective measures the national authority directs to prevent and neutralize the effects of a threat or breach affecting its clients' information systems.

Article 32 requires a digital service provider specifically to identify the risks threatening the security of its own networks and information systems, and to take the technical and organizational measures needed to manage those risks, avoid incidents, and minimize their impact, so as to guarantee the continuity of its services.

Article 34 lets the national authority, on being informed that a digital service provider does not meet an obligation the law imposes, subject that provider to a compliance audit at its own cost, and order its directors to come into compliance within a deadline the authority sets.

A violation of Article 26 or of Article 32 or 34 draws a fine of 100,000 to 200,000 dirhams under Article 50, doubled on recidivism within four years under Article 52; Article 29's protective-measures duty is not among the provisions Article 50 lists.

The Direction Générale de la Sécurité des Systèmes d'Information (DGSSI) describes its own regulatory role as drafting the legislative and regulatory texts relating to cybersecurity and issuing the authorizations and approvals the law contemplates, and operates as the national cybersecurity authority (autorité nationale) Article 1 says is designated by regulation.

When LexLint raises it

  • operates_social_platform

Read the law

Text of Loi n° 05-20 relative à la cybersécurité
as published in Bulletin Officiel n° 6906 and mirrored by DGSSI (Direction Générale de la Sécurité des Systèmes d'Information)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.dgssi.gov.ma/sites/default/files/legislative/brochure/2023-03/loi%2005-20.pdf

Back to the example  ·  Lint your app