{
 "jurisdiction_id": "MA",
 "jurisdiction": "Morocco",
 "url": "https://dataprotection.gi/jurisdictions/morocco/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 26,
  "sub_modules": 57,
  "source_register": 11
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive omnibus law and operational regulator exist, but gap-analysis-identified limits on CNDP powers and unconfirmed territorial scope pull the rating down from green.",
   "claims": [
    {
     "statement": "The Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) is Morocco's national data protection supervisory authority responsible for overseeing compliance with Law No. 09-08.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/morocco-cndp-and-public-ministry-agree-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Personal data protection in Morocco is governed by Law n° 09-08 of 18 February 2009 relating to the protection of individuals with respect to the processing of personal data, and its Implementation Decree n° 2-09-165 of 21 May 2009.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In March 2020, CNDP announced measures including plans to revise national data protection laws and promote privacy-by-design, alongside internal reorganisation to speed up processing of notifications.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/morocco-cndp-announces-new-measures-compliance-and",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "A Morocco-EU gap-analysis study found convergence between Law 09-08 and the GDPR on definitions, material scope of the law, and the principles of data processing.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "CNDP opened a national data protection register for controller filings/notifications.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccos-cndp-opens-national-data-protection-register/",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core principles exist but consent standards and special-category coverage materially diverge from GDPR-equivalent baselines.",
   "claims": [
    {
     "statement": "A Morocco-EU gap analysis found convergence between Law 09-08 and the GDPR on the general principles of data processing, though without a GDPR Article-6-style enumerated list of lawful bases.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Morocco-EU gap analysis found that Law 09-08 has no detailed conditions related to the validity of consent, unlike the GDPR's requirements for freely given, specific and informed consent.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The gap analysis identified the absence of references to biometric data or sexual orientation as protected special categories under Law 09-08, diverging from the GDPR's Article 9 special-category regime.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core rights (access, rectification, objection) exist; erasure and portability are absent, and statutory deadlines are unconfirmed.",
   "claims": [
    {
     "statement": "Because the Morocco-EU gap analysis identified only the absence of a right to be forgotten and a right to data portability as divergences in data subject rights, rights of access, rectification and objection under Law 09-08 are inferred to be broadly convergent with the GDPR baseline.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Law 09-08 does not provide data subjects a right to data portability, a gap identified relative to the GDPR.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Law 09-08 does not include a right to be forgotten/erasure right equivalent to GDPR Article 17.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Some accountability practice (DPIA guidance, breach-handling reminders) exists but core GDPR-equivalent duties (DPO, ROPA, retention) are unconfirmed or absent.",
   "claims": [
    {
     "statement": "CNDP has published a decision setting out criteria for when a Data Protection Impact Assessment-type assessment is required for certain processing operations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/morocco-cndp-publishes-decision-dpia-setting-out",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "The Morocco-EU gap analysis found that Law 09-08 lacks a requirement to notify the supervisory authority of personal data breaches, a divergence from the GDPR's Articles 33-34 breach-notification regime.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "CNDP has issued reminders to controllers regarding data-breach handling procedures notwithstanding the absence of a codified statutory breach-notification obligation.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/morocco-cndp-reminds-controllers-data-breach-procedure",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "A transfer mechanism and authorisation process exist, but EU adequacy remains unresolved and SCC/BCR/localisation instruments are unconfirmed.",
   "claims": [
    {
     "statement": "Morocco requested an EU adequacy recognition decision as early as 2009, and this request remains reported as pending.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Law 09-08's principles applicable to trans-border data transfers were found to converge with the GDPR's approach in a Morocco-EU gap analysis.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "CNDP approved an expedited process to authorise certain cross-border personal data transfers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/morocco-cndp-approves-expedited-process-allow-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "red",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Only one sub-module (health, via genomic-data recommendations) has sourced evidence; the remaining six sub-modules carry no confirmed sectoral overlay.",
   "claims": [
    {
     "statement": "CNDP has presented recommendations specifically addressing the processing of genomic data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/morocco-cndp-presents-recommendations-genomic-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No comprehensive or sector-specific adtech/commercial-privacy regime was identified for this JID beyond the general data protection law.",
   "claims": []
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric data is confirmed excluded from special-category protection and most sub-modules (profiling, ADM transparency, AI risk assessment, surveillance carve-outs) carry no sourced findings.",
   "claims": [
    {
     "statement": "The Morocco-EU gap analysis found that Law 09-08 does not include biometric data within its special-category definitions, unlike GDPR Article 9.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "CNDP has issued recommendations concerning genomic data processing, indicating regulatory attention to genetic data despite the absence of a dedicated statutory genetic-data category in Law 09-08.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/morocco-cndp-presents-recommendations-genomic-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Only an awareness/education initiative is sourced; no statutory age-verification, parental-consent, minor-profiling-ban, or dependent-adult provisions were confirmed.",
   "claims": [
    {
     "statement": "CNDP launched the 'Koun3labal' platform to raise awareness among children, adolescents, parents, guardians and teachers about digital privacy opportunities, dangers, risks, rights and remedies.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/b/moroccos-cndp-launches-platform-on-privacy-protections-personal-data-processing",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/morocco/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Institutional enforcement cooperation and international engagement exist, but CNDP's statutory powers are reportedly limited and collective-redress/private-right-of-action mechanisms are unconfirmed.",
   "claims": [
    {
     "statement": "The Morocco-EU gap analysis identified limits on the powers granted to CNDP as an area of divergence from the GDPR's enforcement framework for supervisory authorities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/moroccan-data-protection-law-moving-to-align-with-eu-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "CNDP and Morocco's Public Ministry agreed in January 2019 on a collaborative roadmap including a case-tracking system and a dedicated prosecution unit for data-protection cases referred by CNDP.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/morocco-cndp-and-public-ministry-agree-data-protection",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "CNDP was among 12 data protection authorities from six continents that signed a joint statement addressed to major social media companies in August 2023.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "Office of the Privacy Commissioner of Canada",
     "source_url": "https://www.priv.gc.ca/en/privacy-and-transparency-at-the-opc/proactive-disclosure/opc-parl-bp/ethi_20231025/is_20231025/?wbdisable=true",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "In May 2026, CNDP presented recommendations on the processing of genomic data, representing the most recently reported CNDP regulatory guidance activity within the evaluation window.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/morocco-cndp-presents-recommendations-genomic-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Commentary characterises Law 09-08 as championing fair and lawful data processing while facing ambiguous definitions and limited enforcement resources.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/evaluating-data-privacy-across-africa-toward-a-unified-gdpr-inspired-framework",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}