Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Law No. 09-08 (2009) establishes Morocco's data protection framework, creating the Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP) as the supervisory authority. The law defines data subject rights (access, rectification, opposition, erasure), obligations for data controllers and processors, requirements for lawful processing, cross‑border data transfer restrictions, security measures, and administrative penalties. It was amended by Decree No. 2-20-03 in 2020, which updated provisions on data breach notification, electronic communications, and introduced additional safeguards for sensitive data. The law aligns with many principles of the EU GDPR but is not considered fully equivalent.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Chapter I - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 6 | Writing |
Chapter II - Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 5 | Prohibited AI Practices |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
Chapter III - Obligations of Data Controllers
| Code | Title |
|---|---|
| Art. 12 | Record-Keeping |
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 20 | Corrective Actions and Duty of Information |
Chapter IV - Security and Confidentiality
| Code | Title |
|---|---|
| Art. 23 | Transitional Provisions |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
Chapter V - International Data Transfers
| Code | Title |
|---|---|
| Art. 43 | Mediation of Disputes |
| Art. 44 | Right to Effective Judicial Remedy |
Chapter VI - National Control Commission (CNDP)
| Code | Title |
|---|---|
| Art. 27 | Fundamental Rights Impact Assessment for High-Risk AI Systems |
| Art. 30 | Privacy Policy |
Chapter VII - Penalties
| Code | Title |
|---|---|
| Art. 53 | Obligations for Providers of General-Purpose AI Models |
| Art. 57 | Transitional Provisions |
| Art. 62 | Entry into Force |
Data Lifecycle
| Code | Title |
|---|---|
| MA-0908-09 | Retention Proportionate to Purpose |
Enforcement
| Code | Title |
|---|---|
| MA-0908-16 | Sanctions for Non Compliance |
Governance
| Code | Title |
|---|---|
| MA-0908-15 | Designation of Correspondent or DPO |
Individual Rights
| Code | Title |
|---|---|
| MA-0908-05 | Data Subject Rights |
International Transfers
| Code | Title |
|---|---|
| MA-0908-06 | Cross Border Data Transfer Authorisation |
Lawfulness
| Code | Title |
|---|---|
| MA-0908-02 | Lawful Basis for Processing |
Marketing
| Code | Title |
|---|---|
| MA-0908-10 | Direct Marketing and Electronic Communications |
Online Privacy
| Code | Title |
|---|---|
| MA-0908-14 | Cookies and Online Tracking |
Processor Management
| Code | Title |
|---|---|
| MA-0908-08 | Subcontractor (Processor) Obligations |
Regulator Notification
| Code | Title |
|---|---|
| MA-0908-01 | Prior Declaration or Authorisation to CNDP |
Security
| Code | Title |
|---|---|
| MA-0908-07 | Security and Confidentiality Measures |
Sensitive Data
| Code | Title |
|---|---|
| MA-0908-04 | Sensitive Data Processing |
| MA-0908-12 | Biometric Access Control Authorisation |
Specific Processing
| Code | Title |
|---|---|
| MA-0908-13 | Whistleblower Hotlines |
Strategic Alignment
| Code | Title |
|---|---|
| MA-0908-17 | Convention 108 Alignment and Modernisation |
Transparency
| Code | Title |
|---|---|
| MA-0908-03 | Information to the Data Subject |
Workplace Monitoring
| Code | Title |
|---|---|
| MA-0908-11 | Video Surveillance and Geolocation in the Workplace |
Your Compliance Coverage
If you comply with Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data, you already cover:
EU AI Act
30%
12 controls mapped
Compare →Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)
30%
12 controls mapped
Compare →Serbia Law on Personal Data Protection (2018)
30%
12 controls mapped
Compare →+ 599 more: Russia Federal Law on Personal Data (152-FZ) (30%), EU In Vitro Diagnostic Medical Devices Regulation (IVDR) (30%)
See all 602 mapped frameworks ↓Maps to 602 other frameworks
Frequently Asked Questions
What is Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data?
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data is a compliance framework from Morocco with 23 domains and 40 controls. Law No. 09-08 (2009) establishes Morocco's data protection framework, creating the Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP) as the supervisory authority. The law defines data subject rights (access, rectification, opposition, erasure), obligations for data controllers and processors, requirements for lawful processing, cross‑border data transfer restrictions, security measures, and administrative penalties. It was amended by Decree No. 2-20-03 in 2020, which updated provisions on data breach notification, electronic communications, and introduced additional safeguards for sensitive data. The law aligns with many principles of the EU GDPR but is not considered fully equivalent. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data have?
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data has 40 controls organised across 23 domains. The largest domains are Chapter I - General Provisions (5 controls), Chapter II - Rights of Data Subjects (5 controls), Chapter III - Obligations of Data Controllers (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data map to?
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data maps to 602 other compliance frameworks. The top mapping partners are EU AI Act (30% coverage), Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) (30% coverage), Serbia Law on Personal Data Protection (2018) (30% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data compliance?
Start your Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required