Lundi – Vendredi : 09:00 – 18:00

Morocco Data Protection Compliance for International Companies: Law No. 09-08 and the CNDP

For international companies operating in Morocco, data protection compliance is not limited to GDPR requirements or to the privacy policies adopted by the group at headquarters level.

Morocco has its own data protection framework, primarily governed by Law No. 09-08 relating to the protection of individuals with regard to the processing of personal data (Loi n° 09-08 relative à la protection des personnes physiques à l’égard du traitement des données à caractère personnel).

Compliance is supervised by the Moroccan Data Protection Authority (Commission Nationale de contrôle de la protection des Données à caractère Personnel – CNDP).

This creates an important practical issue for multinational groups: a data processing operation that has already been reviewed under the GDPR or another foreign privacy regime may still trigger separate compliance and notification requirements in Morocco.

This guide provides an overview of the main issues international companies should consider when processing personal data in connection with their Moroccan operations.

Does Moroccan Data Protection Law Apply to Your Company?

Companies operating in Morocco routinely process personal data, sometimes without identifying the relevant operations as separate data processing activities.

Typical examples include:

  • employee and payroll management;
  • recruitment and candidate databases;
  • customer relationship management (CRM);
  • supplier and business contact databases;
  • website contact forms;
  • customer accounts and online platforms;
  • marketing and newsletters;
  • access control systems;
  • CCTV and workplace security systems;
  • whistleblowing systems;
  • cloud-based HR, accounting or collaboration tools;
  • transmission of employee or customer information to a foreign parent company.

For a Moroccan subsidiary of an international group, several of these activities may involve both local processing in Morocco and international data flows.

The fact that a system, software solution or internal policy has been implemented globally by the parent company does not, by itself, ensure compliance with Moroccan requirements.

Key point

The fact that a system or internal policy has been implemented globally by a parent company does not, by itself, ensure compliance with Moroccan requirements. Law No. 09-08 applies independently to any processing operation falling within its scope.

The Main Principles Under Law No. 09-08

Moroccan data protection law imposes several fundamental obligations on organisations processing personal data.

Personal data must, in particular, be collected and processed fairly, lawfully and transparently, for specific and legitimate purposes.

Companies should ensure that the data collected is necessary and proportionate to the purpose of the relevant processing operation.

They must also take appropriate measures to ensure the accuracy of the data and protect personal information against unauthorised access, alteration, loss, destruction or unlawful disclosure.

This means that compliance is not simply a matter of filing forms with the CNDP.

Companies should be able to identify:

  • what personal data they collect;
  • whose data they process;
  • why the information is collected;
  • who has access to it;
  • which service providers receive it;
  • where the information is stored;
  • how long it is retained; and
  • whether it is transferred outside Morocco.

For international groups, this mapping exercise is particularly important because personal data frequently circulates between the Moroccan entity, the foreign headquarters and external service providers.

CNDP Notification Requirements

One of the important features of the Moroccan framework is the existence of prior notification formalities before the CNDP.

Depending on the nature of the processing operation, the company may be required to submit either a prior declaration or a request for prior authorisation.

As a general rule, processing operations falling within the scope of Law No. 09-08 must be notified unless they benefit from a specific exemption or are subject to a different notification regime.

Certain processing activities require prior authorisation rather than a standard declaration. This may notably concern processing involving:

  • sensitive personal data;
  • health or genetic data;
  • criminal offences or convictions;
  • the Moroccan national identity card number (CIN);
  • a change in the original purpose for which personal data was collected; or
  • certain interconnections between databases having different primary purposes.

The appropriate procedure therefore depends on the actual processing operation and not merely on the company’s sector of activity.

Employee Data: A Key Compliance Area for Foreign Groups

Human resources are often one of the first areas that international companies should review.

A Moroccan employer may process significant amounts of information concerning its employees, including:

  • identification and contact information;
  • employment contracts;
  • salary and payroll information;
  • bank details;
  • attendance and leave records;
  • performance information;
  • disciplinary records;
  • medical or occupational health information; and
  • copies of identification documents.

The CNDP has adopted a specific framework for personal data processing carried out by private-sector organisations for human resources management.

Consequently, using the group’s standard employment documentation or GDPR employee privacy notice may not be sufficient.

Moroccan employment documentation and internal processes should be reviewed to determine whether the required information clauses, contractual provisions and CNDP formalities have been properly implemented.

This issue becomes particularly important when the group’s HR department is located outside Morocco.

Transfers of Personal Data Outside Morocco

International data transfers are one of the most important compliance issues for multinational companies operating in Morocco.

A transfer may arise whenever personal data collected in Morocco is transmitted, accessed, hosted or otherwise made available outside the country.

Examples may include:

  • employee information transmitted to the European headquarters;
  • payroll or HR information processed through an international HR platform;
  • customer information stored on foreign servers;
  • CRM databases accessible by teams outside Morocco;
  • cloud-based software hosted abroad;
  • reporting systems shared with a parent company;
  • foreign IT support having access to Moroccan databases; or
  • data shared with an overseas service provider.

Under Moroccan law, international transfers are subject to specific rules.

Depending on the destination country and the circumstances of the transfer, the transfer may rely on a legally recognised basis or require express authorisation from the CNDP.

Where authorisation is required, contractual safeguards or internal corporate rules may form part of the protection mechanism considered by the CNDP.

Importantly, the international transfer procedure does not replace the compliance requirements applicable to the underlying processing operation.

In practice, the underlying processing must first have been properly declared or authorised before the corresponding international transfer can be approved.

This sequencing can be particularly important when an international group is launching a new HR system, CRM, cloud solution or shared database involving its Moroccan subsidiary.

Key point

The underlying processing must first have been properly declared or authorised before the corresponding international transfer can be approved by the CNDP. This sequencing is critical when deploying a new HR, CRM or cloud solution involving a Moroccan subsidiary.

GDPR Compliance Does Not Automatically Mean Moroccan Compliance

International companies sometimes assume that compliance with the EU General Data Protection Regulation (GDPR) is sufficient for their Moroccan operations.

This should be approached with caution.

Although a multinational group’s GDPR programme may provide a strong compliance foundation, Moroccan Law No. 09-08 remains independently applicable where the relevant processing falls within its scope.

There are procedural differences between the two systems.

In particular, Moroccan law maintains CNDP notification and authorisation mechanisms for a number of processing operations and international transfers.

A group may therefore have:

  • GDPR-compliant privacy notices;
  • data processing agreements;
  • records of processing activities;
  • internal data protection policies; and
  • group-wide security standards;

while still needing to complete additional Moroccan formalities.

For this reason, international companies should not simply duplicate their European documentation for their Moroccan subsidiary without conducting a local legal review.

Practical consequence

A group may have full GDPR-compliant documentation — privacy notices, data processing agreements, records of processing activities — while still needing to complete separate CNDP notification and authorisation procedures for its Moroccan operations.

Cloud Services and International Software Platforms

Cloud infrastructure deserves particular attention.

A Moroccan subsidiary may use software selected globally by its parent company for:

  • human resources;
  • payroll;
  • accounting;
  • customer management;
  • document storage;
  • email;
  • collaboration;
  • marketing; or
  • cybersecurity.

The relevant question is not simply where the software provider is incorporated.

Companies should determine where the personal data is actually hosted, accessed and transferred.

For example, the use of an international SaaS solution may result in Moroccan personal data being hosted abroad or accessed by foreign entities, potentially triggering international transfer requirements.

Before deploying a global solution in Morocco, companies should therefore review the data flows and determine the CNDP formalities applicable to both the underlying processing and any transfer abroad.

Practical consequence

The relevant question is not where the software provider is incorporated. Companies should determine where Moroccan personal data is actually hosted, accessed and transferred — and assess the applicable CNDP formalities before deploying any global SaaS solution in Morocco.

Information Provided to Employees, Customers and Other Data Subjects

Individuals whose personal data is collected must receive appropriate information regarding the processing of their data.

Depending on the circumstances, companies should review their:

  • employment contracts;
  • employee privacy notices;
  • recruitment forms;
  • customer forms;
  • website privacy policies;
  • contact forms;
  • contractual documentation;
  • consent mechanisms; and
  • internal policies.

The documentation should accurately reflect the processing carried out in Morocco.

Simply referring users to a global privacy policy drafted for another jurisdiction may create inconsistencies if the document does not address Moroccan legal requirements or the actual data flows involving the Moroccan entity.

Data Processors and Service Providers

International companies frequently outsource activities involving personal data to third parties.

These may include:

  • payroll providers;
  • accountants;
  • IT service providers;
  • cloud providers;
  • recruitment agencies;
  • marketing providers;
  • call centres;
  • security companies; and
  • other professional service providers.

The company should determine the role played by each provider and ensure that appropriate contractual protections are in place.

The CNDP specifically refers to contractual confidentiality safeguards in the context of several notification procedures.

International companies should therefore include their Moroccan service-provider relationships in their data protection compliance review rather than limiting the analysis to internal databases.

A Practical Compliance Checklist for International Companies

A foreign group with operations in Morocco should generally consider the following steps.

Step 1 – Map the processing activities

Identify the personal data processed by the Moroccan entity, including employee, candidate, customer, supplier and website data.

Step 2 – Map international data flows

Determine whether Moroccan personal data is accessed, stored or transmitted outside Morocco.

This should include transfers to headquarters, affiliated companies, cloud providers and external service providers.

Step 3 – Review the legal basis and purpose of each processing activity

The company should determine why each category of personal data is processed and whether the information collected is proportionate to that purpose.

Step 4 – Identify the applicable CNDP procedure

Determine whether each relevant processing activity requires:

  • a prior declaration;
  • prior authorisation;
  • a specific simplified procedure; and/or
  • an international data transfer request.

Step 5 – Review notices and contractual documentation

Ensure that employment contracts, privacy notices, website documentation, consent forms and other relevant documents comply with Moroccan requirements.

Step 6 – Review service-provider agreements

Verify that agreements with processors and other third parties contain appropriate confidentiality and data protection provisions.

Step 7 – Review international transfers

Identify the destination countries, recipients, hosting arrangements and safeguards applicable to each transfer.

Step 8 – Maintain compliance when systems change

New software, a new service provider, a new HR platform or a new group-wide database may change the company’s data flows and therefore its compliance requirements.

Data protection compliance should consequently be reviewed when significant new systems or processing activities are introduced.

Particular Attention for Moroccan Subsidiaries of International Groups

For a Moroccan subsidiary, compliance should not be analysed in isolation from the group’s wider organisation.

A useful review will often involve coordination between:

  • the Moroccan management team;
  • the local HR department;
  • the group’s legal or compliance department;
  • the group’s IT department;
  • the Data Protection Officer, where applicable; and
  • Moroccan legal counsel.

The objective is not necessarily to replace the group’s existing GDPR or international privacy programme.

Rather, the objective is to identify the Moroccan-specific requirements and integrate them into the group’s existing compliance framework.

This approach can avoid unnecessary duplication while ensuring that local regulatory requirements are properly addressed.

Key point

The objective is not to replace the group’s existing GDPR programme. It is to identify the Moroccan-specific requirements and integrate them into the group’s existing compliance framework — avoiding unnecessary duplication while ensuring local regulatory requirements are properly addressed.

conclusion

Data protection compliance in Morocco requires more than the adoption of a privacy policy.

For international companies, the main challenges often arise from the interaction between Moroccan operations and global corporate systems: employee databases managed by foreign headquarters, cloud platforms, international CRM systems, group reporting tools and cross-border service providers.

Companies operating in Morocco should therefore assess both their local processing activities and their international data flows, identify the appropriate CNDP formalities and ensure that their contractual and information documentation reflects Moroccan law.

A compliance review conducted before deploying a new system or transferring data internationally can significantly reduce regulatory and operational risks.

Cabinet Jawhari · Casablanca

Do you need legal assistance with data protection compliance in Morocco?

Compliance audit

Mapping of processing activities, data flows and applicable CNDP formalities

CNDP filings

Preparation and filing of declarations, authorisation requests and international transfer applications

HR & employment documentation

Review of employment contracts, employee privacy notices and HR processes under Moroccan law

Privacy notices & contracts

Drafting and review of privacy policies, data protection clauses and processor agreements

International transfer review

Assessment of data flows between Morocco and headquarters, cloud providers and foreign service providers

GDPR-to-Morocco gap analysis

Identifying Moroccan-specific requirements to integrate into an existing group-level compliance framework

+212 5 20 44 44 47 · maha@avocat-jawhari.com

Contact us →