Skip to content

Evidence request lists

Law No. 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-Border Transfer + CNDP Authorisation + Adequacy

MA-0908-Cross-Border-Data-Transfer-Authorisation-Article-43-44-CNDP-Adequacy-SCC-BCR
Morocco Law 09-08 Cross-Border Transfer + CNDP Authorisation + Adequacy + SCC

Morocco Law 09-08 Articles 43-44 Cross-Border Data Transfer Regime. Transfer of personal data to a State outside Morocco requires CNDP prior authorisation + assessment of adequate level of protection (niveau de protection adequat). CNDP publishes White List of jurisdictions deemed to provide adequate protection (typically EU/EEA + UK + Switzerland + Convention 108 parties). Transfers to non-adequate jurisdictions require: (1) explicit informed consent of data subject; (2) performance of contract; (3) public interest; (4) vital interests; (5) legal claims; (6) CNDP-approved Standard Contractual Clauses (SCCs - CNDP-published model 2017); (7) CNDP-approved Binding Corporate Rules (BCRs - intra-group transfers within multinational groups); (8) CNDP-approved Codes of Conduct + Certification. Article 44 specific safeguards + supplementary measures + Transfer Impact Assessment + Schrems II con

Artefacts an auditor will ask for
  • Cross-border transfer inventory
  • CNDP authorisation evidence per transfer
  • CNDP-approved SCC executed copies
  • CNDP-approved BCRs
  • Schrems II Transfer Impact Assessment
  • White List reliance documentation
Where this commonly fails
  • Transfer without CNDP authorisation
  • Old SCCs not CNDP-approved
  • No TIA
  • Missing flow-down to processors

DPO + Sanctions + Convention 108 + Modernisation

MA-0908-DPO-Correspondent-Sanctions-Convention-108-Modernisation-Articles-15-31-32-CNDP-Investigations
Morocco Law 09-08 DPO Correspondent + Sanctions + Convention 108 + Modernisation + Articles 15-32

Morocco Law 09-08 governance + enforcement framework. Designation of Correspondent or DPO (Correspondant a la Protection des Donnees) - voluntary under current Law 09-08 + mandatory under 2025 modernisation amendments for: (a) public bodies; (b) large-scale sensitive data processors; (c) systematic monitoring + profiling; (d) multinational controllers + processors. DPO qualifications + independence + reporting to highest management + sufficient resources + CNDP-published register + ANPD-style training programmes. Articles 31-32 Sanctions for Non-Compliance: (1) Administrative sanctions by CNDP - warnings + reprimands + temporary or permanent ban on processing + administrative fines MAD 10,000-300,000 per violation + cumulative; (2) Criminal sanctions Article 51 - imprisonment 3 months to 2 years + fines MAD 10,000-300,000 + aggravated penalties for sensitive data + repeat offences + corp

Artefacts an auditor will ask for
  • DPO designation records (voluntary or mandatory 2025)
  • CNDP investigation response plan
  • Sanctions exposure register (MAD 10K-300K + criminal)
  • Convention 108+ alignment memo
  • Modernisation Bill 2026 readiness gap analysis
  • Administrative Court review procedure
Where this commonly fails
  • No DPO
  • No CNDP response plan
  • No sanctions exposure analysis
  • No Convention 108 alignment review
  • No Modernisation readiness gap analysis

Lawful Basis + Consent + Notice + Article 4-6

MA-0908-Lawful-Basis-Consent-Notice-Information-Article-4-5-6-Specific-Informed-Unambiguous
Morocco Law 09-08 Lawful Basis + Consent + Notice + Article 4-5-6 + Specific Informed

Morocco Law 09-08 Articles 4-6 + 19-21 Lawful Basis for Processing. Consent of the data subject (consentement) - explicit + specific + informed + free + unambiguous + withdrawable + revocable + special form for minors via legal guardian + verifiable. Alternative lawful bases: (1) Compliance with legal obligation; (2) Performance of contract with data subject; (3) Vital interests of data subject; (4) Public interest task; (5) Legitimate interests not overridden by data subject fundamental rights + freedoms (narrower than GDPR Article 6(1)(f)). Information to data subject (Article 5) must cover: identity of controller + Moroccan establishment + purposes + categories + recipients + retention + Cross-Border transfer destinations + safeguards + data subject rights + CNDP complaint avenue + free Arabic + French notice. Article 21 specific requirements for direct collection vs indirect collecti

Artefacts an auditor will ask for
  • Lawful basis register per processing
  • Consent records (granular and withdrawable)
  • Arabic + French privacy notices
  • Direct collection notification evidence
  • Indirect collection notification within 1 month
  • Withdrawal mechanism as easy as giving
Where this commonly fails
  • Bundled consent
  • Notices not in Arabic
  • Indirect collection notice missing
  • No withdrawal mechanism

Prior Declaration + Authorisation + CNDP + Public Register

MA-0908-Prior-Declaration-Authorisation-CNDP-Article-12-Notification-Registration-Public-Register
Morocco Law 09-08 Prior Declaration + Authorisation + CNDP + Article 12 + Public Register

Morocco Law 09-08 Articles 12 + 19 + 27 Prior Declaration and Authorisation Regime (NOTE: Morocco retains pre-GDPR registration model rather than GDPR accountability model). Standard processing requires prior declaration (declaration prealable) to CNDP via electronic portal cndp.ma + free of charge + within 30 days before processing commencement + describing categories + purposes + recipients + retention + safeguards + Cross-Border transfer destination. Sensitive personal data + interconnection + Cross-Border transfer + biometric + criminal record + medical research processing require prior authorisation (autorisation prealable) - CNDP review + 60-day response + may impose conditions + grant + refuse. Public Register of declarations and authorisations maintained by CNDP + freely accessible via website + searchable + transparency function. Single-window for multi-category declarations + s

Artefacts an auditor will ask for
  • CNDP prior declaration receipt
  • Authorisation grant evidence
  • Renewal records
  • Exemption documentation
  • Sector-specific Code of Conduct adoption
  • Single-window submission evidence
Where this commonly fails
  • Processing without declaration
  • Sensitive data without authorisation
  • No renewal
  • No Code of Conduct adoption

Scope + Law 09-08 + Dahir 1-09-15 + CNDP + Convention 108

MA-0908-Scope-Application-Law-09-08-Dahir-1-09-15-18-February-2009-Effective-23-November-2009-CNDP-Convention-108
Morocco Law 09-08 Scope and Application + Dahir 1-09-15 + 18 February 2009 + CNDP

Kingdom of Morocco Law No. 09-08 on the Protection of Individuals with regard to the Processing of Personal Data (Loi No 09-08 relative a la protection des personnes physiques a legard du traitement des donnees a caractere personnel) promulgated by Dahir No. 1-09-15 of 18 February 2009 + published Official Bulletin No. 5711 of 5 March 2009 + effective 23 November 2009. Morocco was the first North African country with a comprehensive personal data protection statute. Implementing decree No. 2-09-165 of 21 May 2009. Commission Nationale de Controle de la Protection des Donnees a Caractere Personnel (CNDP) established as independent regulatory authority + Rabat headquarters + President + Members appointed by King + administrative + budgetary independence. Article 1-3 scope universal application to controllers + processors processing personal data in Morocco + extraterritorial application wh

Artefacts an auditor will ask for
  • Applicability assessment
  • Personal data inventory
  • CNDP engagement records
  • Legal opinion on Moroccan provisions
  • Implementing decree compliance evidence
  • Constitutional Article 24 compliance memo
Where this commonly fails
  • Treating Law 09-08 same as GDPR
  • No CNDP registration
  • Missing Arabic + French notices
  • No Convention 108 alignment review

Security + Subcontractor + Retention + CCTV + Cookies

MA-0908-Security-Subcontractor-Retention-Video-CCTV-Workplace-Cookies-Marketing-Articles-23-30
Morocco Law 09-08 Security + Subcontractor + Retention + Video CCTV + Cookies + Marketing

Morocco Law 09-08 Articles 23-30 + supplementary CNDP Guidelines. Article 23 Security and Confidentiality Measures - appropriate technical + organisational measures proportionate to risk + nature of data + harm + state-of-the-art + encryption + access control + authentication + logging + monitoring + vulnerability management + secure SDLC + business continuity + backup + incident response + Cloud Security Codes of Conduct alignment. Article 24 Subcontractor (sous-traitant) / Processor Obligations - written contract specifying categories + purposes + duration + obligations + security + confidentiality + sub-processing prior written authorisation + audit rights + breach notification + return + deletion at termination + flow-down to sub-processors. Article 25 Retention proportionate to purpose - explicit retention schedule + secure deletion + anonymisation alternative + sector-specific rete

Artefacts an auditor will ask for
  • Security baseline configuration
  • Subcontractor contracts (KDPPR Article 24 compliant)
  • Retention schedule by sector
  • CCTV signage Arabic + French + DPIA
  • Cookies banner + granular controls (CNDP 2024 Guideline)
  • Direct marketing opt-in evidence
Where this commonly fails
  • No subcontractor contracts
  • Missing retention schedule
  • CCTV without signage
  • No cookies opt-in
  • No DPIA for monitoring

Sensitive Data + Biometric + Whistleblower + Article 12

MA-0908-Sensitive-Data-Biometric-Access-Whistleblower-Articles-12-Authorisation-Special-Categories
Morocco Law 09-08 Sensitive Data + Biometric + Whistleblower + Authorisation

Morocco Law 09-08 Article 12 Sensitive Personal Data Processing Authorisation. Sensitive data categories (donnees sensibles): racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + health + sexual life + criminal convictions + administrative sanctions + offences. Processing requires CNDP prior authorisation + grounds limited to: explicit consent + public interest authorised by law + vital interests + non-profit body for members + processing made public by data subject + legal claims. Biometric Access Control + Authorisation (Article 12 + CNDP Guidelines): biometric processing for access control + identification + verification of identity requires CNDP authorisation + proportionality assessment + alternative non-biometric option + retention limited + technical safeguards + non-genetic biometric template encryption + secure storage + wo

Artefacts an auditor will ask for
  • Sensitive data inventory
  • CNDP authorisation for sensitive processing
  • Biometric proportionality + alternative + encryption
  • Whistleblower hotline CNDP authorisation + procedures
  • Sensitive consent records
  • Workforce + works council consultation records
Where this commonly fails
  • Sensitive without authorisation
  • Biometric without proportionality
  • Whistleblower without CNDP
  • No alternative to biometric

Subject Rights + Access + Correction + Object + Article 7-11

MA-0908-Data-Subject-Rights-Access-Correction-Erasure-Object-Article-7-8-9-10-11-30-Day-SLA
Morocco Law 09-08 Data Subject Rights + Access + Correction + Erasure + Object + Article 7-11

Morocco Law 09-08 Articles 7-11 Data Subject Rights regime (modeled on Convention 108 + EU Directive 95/46/EC era). Article 7 Right of Information - to be informed of processing existence + purposes + categories + recipients + free + first-instance + reasonable subsequent fee for additional copies. Article 8 Right of Access - to know all personal data held + purpose + categories + recipients + Cross-Border transfer destinations + 30-day response standard + judicial review of refusals. Article 9 Right to Correction (rectification) + Completion + Update + Locking + Erasure of inaccurate + incomplete + outdated + irrelevant data. Article 10 Right to Object (droit dopposition) - to processing on legitimate grounds + absolute right to object to direct marketing. Article 11 Direct Marketing Restrictions - opt-in consent required + opt-out at every communication + Do-Not-Call Register considera

Artefacts an auditor will ask for
  • Rights request SLAs (30-day) + log
  • Access response templates
  • Correction + erasure procedures
  • Direct marketing opt-in + opt-out evidence
  • Appeals to CNDP procedure
  • Administrative Court review path
Where this commonly fails
  • Slow response
  • No appeals path
  • No opt-in for marketing
  • No appeals to CNDP
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.