Morocco Data Protection Law (09-08)
Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data establishes Morocco's data protection framework. Administered by the Commission Nationale de Controle de la Protection des Donnees a Caractere Personnel (CNDP), it aligns with European data protection standards and provides comprehensive rights for individuals and obligations for data processors.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Chapter I - General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 6 | Writing |
Chapter II - Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 5 | Prohibited AI Practices |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
| Art. 9 | Risk Management System |
Chapter III - Obligations of Data Controllers
| Code | Title |
|---|---|
| Art. 12 | Record-Keeping |
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 20 | Corrective Actions and Duty of Information |
Chapter IV - Security and Confidentiality
| Code | Title |
|---|---|
| Art. 23 | Transitional Provisions |
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
Chapter V - International Data Transfers
| Code | Title |
|---|---|
| Art. 43 | Mediation of Disputes |
| Art. 44 | Right to Effective Judicial Remedy |
Chapter VI - National Control Commission (CNDP)
| Code | Title |
|---|---|
| Art. 27 | Fundamental Rights Impact Assessment for High-Risk AI Systems |
| Art. 30 | Privacy Policy |
Chapter VII - Penalties
| Code | Title |
|---|---|
| Art. 53 | Obligations for Providers of General-Purpose AI Models |
| Art. 57 | Transitional Provisions |
| Art. 62 | Entry into Force |
Data Lifecycle
| Code | Title |
|---|---|
| MA-0908-09 | Retention Proportionate to Purpose |
Enforcement
| Code | Title |
|---|---|
| MA-0908-16 | Sanctions for Non Compliance |
Governance
| Code | Title |
|---|---|
| MA-0908-15 | Designation of Correspondent or DPO |
Individual Rights
| Code | Title |
|---|---|
| MA-0908-05 | Data Subject Rights |
International Transfers
| Code | Title |
|---|---|
| MA-0908-06 | Cross Border Data Transfer Authorisation |
Lawfulness
| Code | Title |
|---|---|
| MA-0908-02 | Lawful Basis for Processing |
Marketing
| Code | Title |
|---|---|
| MA-0908-10 | Direct Marketing and Electronic Communications |
Online Privacy
| Code | Title |
|---|---|
| MA-0908-14 | Cookies and Online Tracking |
Processor Management
| Code | Title |
|---|---|
| MA-0908-08 | Subcontractor (Processor) Obligations |
Regulator Notification
| Code | Title |
|---|---|
| MA-0908-01 | Prior Declaration or Authorisation to CNDP |
Security
| Code | Title |
|---|---|
| MA-0908-07 | Security and Confidentiality Measures |
Sensitive Data
| Code | Title |
|---|---|
| MA-0908-04 | Sensitive Data Processing |
| MA-0908-12 | Biometric Access Control Authorisation |
Specific Processing
| Code | Title |
|---|---|
| MA-0908-13 | Whistleblower Hotlines |
Strategic Alignment
| Code | Title |
|---|---|
| MA-0908-17 | Convention 108 Alignment and Modernisation |
Transparency
| Code | Title |
|---|---|
| MA-0908-03 | Information to the Data Subject |
Workplace Monitoring
| Code | Title |
|---|---|
| MA-0908-11 | Video Surveillance and Geolocation in the Workplace |
Your Compliance Coverage
If you comply with Morocco Data Protection Law (09-08), you already cover:
EU AI Act
30%
12 controls mapped
Compare →Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018)
30%
12 controls mapped
Compare →Serbia Law on Personal Data Protection (2018)
30%
12 controls mapped
Compare →+ 609 more: Russia Federal Law on Personal Data (152-FZ) (30%), EU In Vitro Diagnostic Medical Devices Regulation (IVDR) (30%)
See all 612 mapped frameworks ↓Maps to 612 other frameworks
Frequently Asked Questions
What is Morocco Data Protection Law (09-08)?
Morocco Data Protection Law (09-08) is a compliance framework from Morocco with 23 domains and 40 controls. Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data establishes Morocco's data protection framework. Administered by the Commission Nationale de Controle de la Protection des Donnees a Caractere Personnel (CNDP), it aligns with European data protection standards and provides comprehensive rights for individuals and obligations for data processors. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Morocco Data Protection Law (09-08) have?
Morocco Data Protection Law (09-08) has 40 controls organised across 23 domains. The largest domains are Chapter I - General Provisions (5 controls), Chapter II - Rights of Data Subjects (5 controls), Chapter III - Obligations of Data Controllers (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Morocco Data Protection Law (09-08) map to?
Morocco Data Protection Law (09-08) maps to 612 other compliance frameworks. The top mapping partners are EU AI Act (30% coverage), Iceland Data Protection and Processing of Personal Data Act (Act No. 90/2018) (30% coverage), Serbia Law on Personal Data Protection (2018) (30% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Morocco Data Protection Law (09-08) compliance?
Start your Morocco Data Protection Law (09-08) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Morocco Data Protection Law (09-08) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required