Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border Transfer + CNDP Authorisation + Adequacy
Morocco Law 09-08 Articles 43-44 Cross-Border Data Transfer Regime. Transfer of personal data to a State outside Morocco requires CNDP prior authorisation + assessment of adequate level of protection (niveau de protection adequat). CNDP publishes White List of jurisdictions deemed to provide adequate protection (typically EU/EEA + UK + Switzerland + Convention 108 parties). Transfers to non-adequate jurisdictions require: (1) explicit informed consent of data subject; (2) performance of contract; (3) public interest; (4) vital interests; (5) legal claims; (6) CNDP-approved Standard Contractual Clauses (SCCs - CNDP-published model 2017); (7) CNDP-approved Binding Corporate Rules (BCRs - intra-group transfers within multinational groups); (8) CNDP-approved Codes of Conduct + Certification. Article 44 specific safeguards + supplementary measures + Transfer Impact Assessment + Schrems II con
- Cross-border transfer inventory
- CNDP authorisation evidence per transfer
- CNDP-approved SCC executed copies
- CNDP-approved BCRs
- Schrems II Transfer Impact Assessment
- White List reliance documentation
- Transfer without CNDP authorisation
- Old SCCs not CNDP-approved
- No TIA
- Missing flow-down to processors
DPO + Sanctions + Convention 108 + Modernisation
Morocco Law 09-08 governance + enforcement framework. Designation of Correspondent or DPO (Correspondant a la Protection des Donnees) - voluntary under current Law 09-08 + mandatory under 2025 modernisation amendments for: (a) public bodies; (b) large-scale sensitive data processors; (c) systematic monitoring + profiling; (d) multinational controllers + processors. DPO qualifications + independence + reporting to highest management + sufficient resources + CNDP-published register + ANPD-style training programmes. Articles 31-32 Sanctions for Non-Compliance: (1) Administrative sanctions by CNDP - warnings + reprimands + temporary or permanent ban on processing + administrative fines MAD 10,000-300,000 per violation + cumulative; (2) Criminal sanctions Article 51 - imprisonment 3 months to 2 years + fines MAD 10,000-300,000 + aggravated penalties for sensitive data + repeat offences + corp
- DPO designation records (voluntary or mandatory 2025)
- CNDP investigation response plan
- Sanctions exposure register (MAD 10K-300K + criminal)
- Convention 108+ alignment memo
- Modernisation Bill 2026 readiness gap analysis
- Administrative Court review procedure
- No DPO
- No CNDP response plan
- No sanctions exposure analysis
- No Convention 108 alignment review
- No Modernisation readiness gap analysis
Lawful Basis + Consent + Notice + Article 4-6
Morocco Law 09-08 Articles 4-6 + 19-21 Lawful Basis for Processing. Consent of the data subject (consentement) - explicit + specific + informed + free + unambiguous + withdrawable + revocable + special form for minors via legal guardian + verifiable. Alternative lawful bases: (1) Compliance with legal obligation; (2) Performance of contract with data subject; (3) Vital interests of data subject; (4) Public interest task; (5) Legitimate interests not overridden by data subject fundamental rights + freedoms (narrower than GDPR Article 6(1)(f)). Information to data subject (Article 5) must cover: identity of controller + Moroccan establishment + purposes + categories + recipients + retention + Cross-Border transfer destinations + safeguards + data subject rights + CNDP complaint avenue + free Arabic + French notice. Article 21 specific requirements for direct collection vs indirect collecti
- Lawful basis register per processing
- Consent records (granular and withdrawable)
- Arabic + French privacy notices
- Direct collection notification evidence
- Indirect collection notification within 1 month
- Withdrawal mechanism as easy as giving
- Bundled consent
- Notices not in Arabic
- Indirect collection notice missing
- No withdrawal mechanism
Prior Declaration + Authorisation + CNDP + Public Register
Morocco Law 09-08 Articles 12 + 19 + 27 Prior Declaration and Authorisation Regime (NOTE: Morocco retains pre-GDPR registration model rather than GDPR accountability model). Standard processing requires prior declaration (declaration prealable) to CNDP via electronic portal cndp.ma + free of charge + within 30 days before processing commencement + describing categories + purposes + recipients + retention + safeguards + Cross-Border transfer destination. Sensitive personal data + interconnection + Cross-Border transfer + biometric + criminal record + medical research processing require prior authorisation (autorisation prealable) - CNDP review + 60-day response + may impose conditions + grant + refuse. Public Register of declarations and authorisations maintained by CNDP + freely accessible via website + searchable + transparency function. Single-window for multi-category declarations + s
- CNDP prior declaration receipt
- Authorisation grant evidence
- Renewal records
- Exemption documentation
- Sector-specific Code of Conduct adoption
- Single-window submission evidence
- Processing without declaration
- Sensitive data without authorisation
- No renewal
- No Code of Conduct adoption
Scope + Law 09-08 + Dahir 1-09-15 + CNDP + Convention 108
Kingdom of Morocco Law No. 09-08 on the Protection of Individuals with regard to the Processing of Personal Data (Loi No 09-08 relative a la protection des personnes physiques a legard du traitement des donnees a caractere personnel) promulgated by Dahir No. 1-09-15 of 18 February 2009 + published Official Bulletin No. 5711 of 5 March 2009 + effective 23 November 2009. Morocco was the first North African country with a comprehensive personal data protection statute. Implementing decree No. 2-09-165 of 21 May 2009. Commission Nationale de Controle de la Protection des Donnees a Caractere Personnel (CNDP) established as independent regulatory authority + Rabat headquarters + President + Members appointed by King + administrative + budgetary independence. Article 1-3 scope universal application to controllers + processors processing personal data in Morocco + extraterritorial application wh
- Applicability assessment
- Personal data inventory
- CNDP engagement records
- Legal opinion on Moroccan provisions
- Implementing decree compliance evidence
- Constitutional Article 24 compliance memo
- Treating Law 09-08 same as GDPR
- No CNDP registration
- Missing Arabic + French notices
- No Convention 108 alignment review
Security + Subcontractor + Retention + CCTV + Cookies
Morocco Law 09-08 Articles 23-30 + supplementary CNDP Guidelines. Article 23 Security and Confidentiality Measures - appropriate technical + organisational measures proportionate to risk + nature of data + harm + state-of-the-art + encryption + access control + authentication + logging + monitoring + vulnerability management + secure SDLC + business continuity + backup + incident response + Cloud Security Codes of Conduct alignment. Article 24 Subcontractor (sous-traitant) / Processor Obligations - written contract specifying categories + purposes + duration + obligations + security + confidentiality + sub-processing prior written authorisation + audit rights + breach notification + return + deletion at termination + flow-down to sub-processors. Article 25 Retention proportionate to purpose - explicit retention schedule + secure deletion + anonymisation alternative + sector-specific rete
- Security baseline configuration
- Subcontractor contracts (KDPPR Article 24 compliant)
- Retention schedule by sector
- CCTV signage Arabic + French + DPIA
- Cookies banner + granular controls (CNDP 2024 Guideline)
- Direct marketing opt-in evidence
- No subcontractor contracts
- Missing retention schedule
- CCTV without signage
- No cookies opt-in
- No DPIA for monitoring
Sensitive Data + Biometric + Whistleblower + Article 12
Morocco Law 09-08 Article 12 Sensitive Personal Data Processing Authorisation. Sensitive data categories (donnees sensibles): racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + health + sexual life + criminal convictions + administrative sanctions + offences. Processing requires CNDP prior authorisation + grounds limited to: explicit consent + public interest authorised by law + vital interests + non-profit body for members + processing made public by data subject + legal claims. Biometric Access Control + Authorisation (Article 12 + CNDP Guidelines): biometric processing for access control + identification + verification of identity requires CNDP authorisation + proportionality assessment + alternative non-biometric option + retention limited + technical safeguards + non-genetic biometric template encryption + secure storage + wo
- Sensitive data inventory
- CNDP authorisation for sensitive processing
- Biometric proportionality + alternative + encryption
- Whistleblower hotline CNDP authorisation + procedures
- Sensitive consent records
- Workforce + works council consultation records
- Sensitive without authorisation
- Biometric without proportionality
- Whistleblower without CNDP
- No alternative to biometric
Subject Rights + Access + Correction + Object + Article 7-11
Morocco Law 09-08 Articles 7-11 Data Subject Rights regime (modeled on Convention 108 + EU Directive 95/46/EC era). Article 7 Right of Information - to be informed of processing existence + purposes + categories + recipients + free + first-instance + reasonable subsequent fee for additional copies. Article 8 Right of Access - to know all personal data held + purpose + categories + recipients + Cross-Border transfer destinations + 30-day response standard + judicial review of refusals. Article 9 Right to Correction (rectification) + Completion + Update + Locking + Erasure of inaccurate + incomplete + outdated + irrelevant data. Article 10 Right to Object (droit dopposition) - to processing on legitimate grounds + absolute right to object to direct marketing. Article 11 Direct Marketing Restrictions - opt-in consent required + opt-out at every communication + Do-Not-Call Register considera
- Rights request SLAs (30-day) + log
- Access response templates
- Correction + erasure procedures
- Direct marketing opt-in + opt-out evidence
- Appeals to CNDP procedure
- Administrative Court review path
- Slow response
- No appeals path
- No opt-in for marketing
- No appeals to CNDP
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.