Comprehensive regime
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Loi n° 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel promulguée par le Dahir n° 1-09-15 du 22 safar 1430 (18 février 2009)Text of Law No. 09-08 (French, consolidated)
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived December 25, 2023. Publisher's page: https://www.cndp.ma/wp-content/uploads/2023/11/Loi-09-08-Fr.pdfIn force. Binds public and private bodies.
What this law does
Article 2 applies the law to automated and manual processing of personal data by a physical or legal person, public or private, whose controller is established in Morocco or who uses processing means located there. Article 4 requires the data subject's unambiguous consent before processing, unless the processing falls under Article 4's enumerated exceptions (a legal obligation, contract performance, vital interest, a public-interest mission, or the controller's legitimate interest).
Article 12 requires most processing to be the subject of a prior declaration to the CNDP, and requires CNDP prior authorization for sensitive data (Article 1(3): racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or health data including genetic data), which is otherwise prohibited absent the data subject's express consent or another Article 21 ground.
Articles 7 to 9 give the data subject the right to access, rectify, and object to the processing of their data, and a provision preceding Article 7 bars a decision producing legal effects on a person from being based solely on automated processing intended to profile or evaluate an aspect of their personality. Article 10 bars direct marketing by automated call, fax, or electronic mail to a person who has not given prior consent.
Article 43 bars transferring personal data to a foreign state unless that state ensures a sufficient level of protection, as assessed by the CNDP, which maintains a list of adequate states. The CNDP, established by Article 27, supervises compliance, receives declarations and complaints, and issues authorizations.
Breach of these duties is backed by a graduated schedule of fines and, for several offences, imprisonment: an unauthorized or undeclared processing draws a fine of 10,000 to 100,000 dirhams (Article 52); refusing an access, rectification, or objection request draws a fine of 20,000 to 200,000 dirhams per infraction (Article 53); fraudulent or unlawful collection, or processing beyond the declared purpose, draws imprisonment of three months to one year and a fine of 20,000 to 200,000 dirhams (Article 54); an unlawful cross-border transfer draws the same imprisonment and fine range (Article 60); and processing sensitive data without the data subject's express consent draws imprisonment of three months to one year and a fine of 50,000 to 300,000 dirhams, the highest tier in the statute (Article 57).
What it requires