🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
MO · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

Macau SAR

MO schema gdpri-v2 trajectory: not recordedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 26 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
26Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core framework and authority are well-documented (T2), but territorial scope and the precise present-day filing regime lack T1 confirmation.

Primary frameworkLaw n° 09-08 of 18 February 2009 (Protection of Individuals with regard to the Processing of Personal Data) and Implementation Decree n° 2-09-165 of 21 May 2009
Traffic-light rationale — AmberCore framework and authority are well-documented (T2), but territorial scope and the precise present-day filing regime lack T1 confirmation.

Sub-modules (5)

Regulator And AuthorityGreen

CNDP is Morocco's national data-protection supervisory authority under Law 09-08.

Claims (1):

  • The CNDP (Commission Nationale de contrôle de la protection des données à caractère personnel) is Morocco's data protection supervisory authority operating under Law n° 09-08.

Act And InstrumentsGreen

The primary instruments are Law n° 09-08 (2009) and its Implementation Decree n° 2-09-165 (2009).

Claims (1):

  • Personal data protection in Morocco is governed by Law n° 09-08 of 18 February 2009 and its Implementation Decree n° 2-09-165 of 21 May 2009.

Material ScopeAmber

A 2018 CNDP/EU gap analysis found convergence between Law 09-08's material scope and the GDPR's.

Claims (1):

  • A CNDP/EU Delegation gap analysis found that the material scope of Law 09-08 converges with the GDPR's material scope of application.

Territorial ScopeAmber

Law 09-08 was enacted partly with an EU-facing offshoring/outsourcing orientation, but no explicit GDPR Art 3-style extraterritoriality clause was confirmed in research.

Claims (1):

  • Law 09-08 was initially enacted partly to encourage offshoring/outsourcing of processing activities relating to European residents' personal data, giving it an EU-facing orientation, though no explicit codified extraterritorial-applicability clause equivalent to GDPR Art 3 was confirmed.

Regulator Registration And FilingGreen

CNDP operates a national online register through which controllers file processing declarations/notifications.

Claims (1):

  • CNDP operates a national online data-protection register/portal through which controllers file processing notifications.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative49 words

Morocco has a comprehensive omnibus data-protection statute, Law n° 09-08, supervised by the CNDP. Research found convergence between the law's material scope, processing principles, and trans-border transfer principles and the GDPR framework, per a 2018 CNDP/EU-Delegation gap analysis, but no evidence of a GDPR-style explicit extraterritoriality clause was located.

Sources and claims (5)
  1. ConfirmedIAPPThe CNDP (Commission Nationale de contrôle de la protection des données à caractère personnel) is Morocco's data protection supervisory authority operating under Law n° 09-08.observed
  2. ConfirmedIAPPPersonal data protection in Morocco is governed by Law n° 09-08 of 18 February 2009 and its Implementation Decree n° 2-09-165 of 21 May 2009.observed
  3. ProbableIAPPA CNDP/EU Delegation gap analysis found that the material scope of Law 09-08 converges with the GDPR's material scope of application.observed
  4. UncertainIAPPLaw 09-08 was initially enacted partly to encourage offshoring/outsourcing of processing activities relating to European residents' personal data, giving it an EU-facing orientation, though no explicit codified extraterritorial-applicability clause equivalent to GDPR Art 3 was confirmed.observed
  5. ConfirmedIAPPCNDP operates a national online data-protection register/portal through which controllers file processing notifications.observed

#

Core lawful-basis framework exists but consent and special-category provisions are documented as materially thinner than GDPR equivalents; pseudonymisation regime unconfirmed.

Primary frameworkLaw n° 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberCore lawful-basis framework exists but consent and special-category provisions are documented as materially thinner than GDPR equivalents; pseudonymisation regime unconfirmed.

Sub-modules (4)

Lawful BasesAmber

Gap analysis found the general principles of data processing under Law 09-08 converge with GDPR-equivalent principles.

Claims (1):

  • A CNDP/EU gap analysis found the general principles of data processing under Law 09-08 to be an area of convergence with GDPR-equivalent processing principles.

Special CategoriesRed

Law 09-08 does not reference biometric data or sexual orientation as special/sensitive categories.

Claims (1):

  • The 2018 gap analysis identified the absence of references to biometric data or sexual orientation as special categories under Law 09-08, diverging from GDPR Art 9.

Pseudonymisation And AnonymisationRed

No pseudonymisation or anonymisation safe-harbour definitions under Moroccan law were located in research.

Absence provenance: No T1/T2/T3 source discussing pseudonymisation or anonymisation standards under Law 09-08 was found.. Searched: CNDP Maroc protection données personnelles 2026, Morocco CNDP data protection law 09-08.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative39 words

The 2018 gap analysis found convergence on general processing principles but identified material gaps relative to GDPR: no detailed consent-validity conditions, and no coverage of biometric data or sexual orientation as special categories. No pseudonymisation/anonymisation safe-harbour provisions were located.

Sources and claims (3)
  1. ProbableIAPPA CNDP/EU gap analysis found the general principles of data processing under Law 09-08 to be an area of convergence with GDPR-equivalent processing principles.observed
  2. ProbableIAPPThe 2018 gap analysis identified the absence of detailed conditions related to the validity of consent under Law 09-08 as a divergence from GDPR consent standards.observed
  3. ProbableIAPPThe 2018 gap analysis identified the absence of references to biometric data or sexual orientation as special categories under Law 09-08, diverging from GDPR Art 9.observed

#

Confirmed statutory gaps on erasure/portability rights; other rights sub-modules unpopulated for lack of sourcing.

Primary frameworkLaw n° 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — RedConfirmed statutory gaps on erasure/portability rights; other rights sub-modules unpopulated for lack of sourcing.

Sub-modules (5)

Access RightRed

No T1/T2 source detailing the subject-access request framework under Law 09-08 was located.

Absence provenance: No detail on access-request mechanics located.. Searched: Morocco CNDP data protection law 09-08.

Rectification And ErasureRed

Gap analysis found Law 09-08 does not provide a right to be forgotten.

Claims (1):

  • The 2018 gap analysis found that Law 09-08 does not provide a right to be forgotten equivalent to GDPR erasure rights.

Restriction And ObjectionRed

No T1/T2 source detailing restriction-of-processing or objection rights under Law 09-08 was located.

Absence provenance: No detail on restriction/objection rights located.. Searched: Morocco CNDP data protection law 09-08.

Data PortabilityRed

Gap analysis found Law 09-08 does not provide a right to data portability.

Claims (1):

  • The 2018 gap analysis found that Law 09-08 does not provide a right to data portability equivalent to the GDPR.

Deadlines And Response WindowsRed

No T1/T2 source detailing statutory controller-response deadlines under Law 09-08 was located.

Absence provenance: No statutory response-window detail located.. Searched: Morocco CNDP data protection law 09-08.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative35 words

The 2018 gap analysis explicitly found Law 09-08 lacks a right to be forgotten and a right to data portability. No T1/T2 sources were located detailing the access-request framework, restriction/objection rights, or statutory response deadlines.

Sources and claims (2)
  1. ProbableIAPPThe 2018 gap analysis found that Law 09-08 does not provide a right to be forgotten equivalent to GDPR erasure rights.observed
  2. ProbableIAPPThe 2018 gap analysis found that Law 09-08 does not provide a right to data portability equivalent to the GDPR.observed

#

Statutory breach-notification gap is a materially significant, confirmed finding; several sub-modules (DPO, security measures, retention) remain unconfirmed.

Primary frameworkLaw n° 09-08 of 18 February 2009 and Implementation Decree n° 2-09-165
Supervisory authorityCNDP
Traffic-light rationale — RedStatutory breach-notification gap is a materially significant, confirmed finding; several sub-modules (DPO, security measures, retention) remain unconfirmed.

Sub-modules (7)

Accountability And DpiaAmber

CNDP published a decision/deliberation addressing DPIA-related criteria, but full text was not accessible in research.

Claims (1):

  • CNDP published a decision setting out criteria relevant to data protection impact assessments (DPIA) for certain processing operations.

Dpo RequirementsRed

No T1/T2 source confirming a DPO appointment threshold under Moroccan law was located.

Absence provenance: No DPO-threshold provision confirmed; general DPO-tracker sources did not list a Morocco-specific entry.. Searched: Morocco law 09-08 DPO data protection officer requirement registration declaration CNDP.

Ropa RequirementsAmber

CNDP's registration/notification portal serves as the functional equivalent of a records-of-processing obligation.

Claims (1):

  • CNDP's national online registration portal requires controllers to declare processing operations, functioning as the Moroccan equivalent of a records-of-processing obligation.

Joint Controller ArrangementsRed

No T1/T2 source addressing joint-controller arrangements under Law 09-08 was located.

Absence provenance: No joint-controller provisions confirmed.. Searched: Morocco CNDP data protection law 09-08.

Security MeasuresRed

No T1/T2 source detailing specific technical/organisational security-measure requirements was located.

Absence provenance: No detailed security-measures provision confirmed.. Searched: Morocco CNDP data protection law 09-08.

Breach NotificationRed

Law 09-08 was found to lack a statutory requirement to notify the CNDP of data breaches; CNDP has separately issued administrative reminders regarding breach-handling procedure.

Claims (2):

  • The 2018 gap analysis found that Law 09-08 lacks a requirement to notify the CNDP of personal data breaches.
  • CNDP has issued administrative reminders to controllers regarding an established data-breach handling procedure, notwithstanding the absence of a codified statutory notification duty.

Retention And DisposalRed

No T1/T2 source detailing retention limits or disposal duties under Law 09-08 was located.

Absence provenance: No retention/disposal provision confirmed.. Searched: Morocco CNDP data protection law 09-08.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative54 words

Research confirms Law 09-08 lacks a statutory data-breach notification requirement to the CNDP, though the CNDP has issued administrative reminders on breach-handling procedure and a decision touching on DPIA-type criteria. The CNDP's registration/notification portal functions as a records-of-processing equivalent. DPO thresholds, joint-controller rules, detailed security-measure requirements, and retention/disposal duties were not confirmed in research.

Sources and claims (4)
  1. ProbableIAPPThe 2018 gap analysis found that Law 09-08 lacks a requirement to notify the CNDP of personal data breaches.observed
  2. UncertainDataGuidanceCNDP has issued administrative reminders to controllers regarding an established data-breach handling procedure, notwithstanding the absence of a codified statutory notification duty.observed
  3. UncertainDataGuidanceCNDP published a decision setting out criteria relevant to data protection impact assessments (DPIA) for certain processing operations.observed
  4. ProbableIAPPCNDP's national online registration portal requires controllers to declare processing operations, functioning as the Moroccan equivalent of a records-of-processing obligation.observed

#

Pending EU adequacy status and Convention 108 accession are confirmed; several transfer-mechanism sub-modules remain unconfirmed.

Primary frameworkLaw n° 09-08 of 18 February 2009; Council of Europe Convention 108
Supervisory authorityCNDP
Traffic-light rationale — AmberPending EU adequacy status and Convention 108 accession are confirmed; several transfer-mechanism sub-modules remain unconfirmed.

Sub-modules (6)

Transfer MechanismsAmber

Transfer principles under Law 09-08 converge with GDPR-equivalent principles; CNDP has an expedited authorization process for certain transfers; Morocco has acceded to Convention 108.

Claims (3):

  • The 2018 gap analysis identified the principles applicable to trans-border data transfers under Law 09-08 as an area of convergence with GDPR's transfer framework.
  • Morocco is among the non-European states that have acceded to the Council of Europe's Convention 108 on the protection of individuals with regard to automatic processing of personal data.
  • CNDP approved an expedited administrative process to authorize certain cross-border personal data transfers.

Adequacy ReceivedAmber

Not applicable in the sense of Morocco receiving adequacy from another regime as primary evidence; research instead confirms Morocco's own pending request for EU adequacy recognition (see adequacy_granted note for directionality).

Claims (1):

  • Morocco requested an EU adequacy recognition decision from the European Commission as early as 2009, and this request remains pending.

Adequacy GrantedRed

No T1/T2 source confirming Morocco has granted adequacy-equivalent recognition to other regimes was located.

Absence provenance: No evidence of Morocco granting adequacy to other jurisdictions.. Searched: Morocco law 09-08 cross-border data transfer authorization CNDP adequacy list.

Sccs And BcrsRed

No T1/T2 source confirming SCC or BCR forms/uptake under Moroccan law was located.

Absence provenance: No SCC/BCR mechanism detail confirmed.. Searched: Morocco law 09-08 cross-border data transfer authorization CNDP adequacy list.

Transfer Impact AssessmentRed

No T1/T2 source confirming a transfer-impact-assessment requirement under Moroccan law was located.

Absence provenance: No TIA requirement confirmed.. Searched: Morocco law 09-08 cross-border data transfer authorization CNDP adequacy list.

Data LocalisationRed

No T1/T2 source confirming data-localisation mandates under Moroccan law was located.

Absence provenance: No data-localisation mandate confirmed.. Searched: Morocco law 09-08 cross-border data transfer authorization CNDP adequacy list.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative69 words

Morocco requested an EU adequacy decision as early as 2009; this request remains pending. Morocco has separately acceded to Council of Europe Convention 108, an international cross-border transfer safeguard mechanism. CNDP has an expedited authorization process for certain transfers. Trans-border transfer principles were flagged as an area of convergence with GDPR in the 2018 gap analysis, but SCC/BCR uptake, transfer-impact-assessment requirements, and data-localisation mandates were not confirmed in research.

Sources and claims (4)
  1. ConfirmedIAPPMorocco requested an EU adequacy recognition decision from the European Commission as early as 2009, and this request remains pending.observed
  2. ProbableIAPPThe 2018 gap analysis identified the principles applicable to trans-border data transfers under Law 09-08 as an area of convergence with GDPR's transfer framework.observed
  3. ConfirmedOPC CanadaMorocco is among the non-European states that have acceded to the Council of Europe's Convention 108 on the protection of individuals with regard to automatic processing of personal data.observed
  4. UncertainDataGuidanceCNDP approved an expedited administrative process to authorize certain cross-border personal data transfers.observed

#

No sectoral overlay evidence found across any sub-module in the searches conducted.

Traffic-light rationale — RedNo sectoral overlay evidence found across any sub-module in the searches conducted.

Sub-modules (7)

Financial Sector OverlayRed

No sector-specific financial data-protection overlay evidence located.

Absence provenance: No financial-sector overlay found.. Searched: Morocco CNDP fine sanction 2025 2026 enforcement.

Health Sector OverlayRed

No sector-specific health data-protection overlay evidence located.

Absence provenance: No health-sector overlay found.. Searched: CNDP Maroc protection données personnelles 2026.

Telecoms And EprivacyRed

No telecoms/ePrivacy-equivalent overlay evidence located.

Absence provenance: No telecoms/ePrivacy overlay found.. Searched: CNDP Maroc protection données personnelles 2026.

Employment DataRed

No employment-data-specific overlay evidence located.

Absence provenance: No employment-data overlay found.. Searched: CNDP Maroc protection données personnelles 2026.

Credit And ScoringRed

No credit-scoring-specific overlay evidence located.

Absence provenance: No credit-scoring overlay found.. Searched: CNDP Maroc protection données personnelles 2026.

EducationRed

No education-sector-specific overlay evidence located beyond the Koun3labal awareness platform (captured under children_and_vulnerable_groups).

Absence provenance: No education-sector legal overlay found.. Searched: CNDP Maroc protection données personnelles 2026.

InsuranceRed

No insurance-sector-specific overlay evidence located.

Absence provenance: No insurance-sector overlay found.. Searched: CNDP Maroc protection données personnelles 2026.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative25 words

No T1/T2/T3 source was located discussing sector-specific data-protection overlays (financial, health, telecoms/ePrivacy, employment, credit-scoring, education, insurance) for Morocco distinct from the general Law 09-08 regime.

#

Only one weakly-sourced sub-module (direct marketing) populated; remainder unconfirmed.

Primary frameworkLaw n° 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — RedOnly one weakly-sourced sub-module (direct marketing) populated; remainder unconfirmed.

Sub-modules (6)

Cookies And TrackersRed

No T1/T2 source on cookie/tracker consent rules under Moroccan law located.

Absence provenance: No cookie/tracker regime confirmed.. Searched: CNDP Maroc protection données personnelles 2026.

Dark PatternsRed

No T1/T2 source on dark-pattern prohibitions under Moroccan law located.

Absence provenance: No dark-pattern rule confirmed.. Searched: CNDP Maroc protection données personnelles 2026.

Opt Out SignalsRed

No T1/T2 source on opt-out signal recognition under Moroccan law located.

Absence provenance: No opt-out signal regime confirmed.. Searched: CNDP Maroc protection données personnelles 2026.

Clean Rooms And DcrRed

No T1/T2 source on data clean rooms under Moroccan law located.

Absence provenance: No clean-room rule confirmed.. Searched: CNDP Maroc protection données personnelles 2026.

Cross Context AdvertisingRed

No T1/T2 source on cross-context advertising/sale-share concepts under Moroccan law located.

Absence provenance: No cross-context advertising rule confirmed.. Searched: CNDP Maroc protection données personnelles 2026.

Direct MarketingAmber

CNDP has issued FAQs addressing direct-marketing communications, though the substantive content was not fully accessible.

Claims (1):

  • CNDP has issued FAQs addressing direct-marketing communications under Law 09-08.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative29 words

Only limited evidence was located: CNDP has issued direct-marketing FAQs. No T1/T2 source on cookies/trackers, dark patterns, opt-out signals, clean rooms, or cross-context advertising under Moroccan law was found.

Sources and claims (1)
  1. UncertainDataGuidanceCNDP has issued FAQs addressing direct-marketing communications under Law 09-08.observed

#

Biometric and genetic-data sub-modules have weak (title-only) evidence; remaining sub-modules unconfirmed.

Primary frameworkLaw n° 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberBiometric and genetic-data sub-modules have weak (title-only) evidence; remaining sub-modules unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

No T1/T2 source on profiling restrictions under Moroccan law located.

Absence provenance: No profiling-restriction provision confirmed.. Searched: Morocco CNDP data protection law 09-08.

Automated Decision Making TransparencyRed

No T1/T2 source on ADM transparency rules under Moroccan law located.

Absence provenance: No ADM transparency provision confirmed.. Searched: Morocco CNDP data protection law 09-08.

Ai Risk AssessmentsRed

No T1/T2 source on AI-specific risk-assessment requirements under Moroccan law located.

Absence provenance: No AI risk-assessment provision confirmed.. Searched: Morocco CNDP data protection law 09-08.

Biometric RegimeAmber

CNDP issued a deliberation addressing facial-recognition technology, though full content was not accessible.

Claims (1):

  • CNDP issued a deliberation addressing the use of facial-recognition technology under the Moroccan data-protection framework.

Genetic DataAmber

CNDP presented recommendations on genomic/genetic data processing, though full content was not accessible.

Claims (1):

  • CNDP presented recommendations concerning the processing of genomic/genetic data.

State Surveillance CarveoutsRed

No T1/T2 source on state-surveillance carveouts under Moroccan law located.

Absence provenance: No state-surveillance carveout provision confirmed.. Searched: Morocco CNDP data protection law 09-08.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative43 words

CNDP has issued a deliberation on facial recognition and recommendations on genomic data, but full substantive content of both was not accessible in research. No T1/T2 source on profiling restrictions, ADM transparency, AI-specific risk assessments, or state-surveillance carveouts under Moroccan law was located.

Sources and claims (2)
  1. UncertainDataGuidanceCNDP issued a deliberation addressing the use of facial-recognition technology under the Moroccan data-protection framework.observed
  2. UncertainDataGuidanceCNDP presented recommendations concerning the processing of genomic/genetic data.observed

#

A non-binding awareness initiative is confirmed; statutory child/vulnerable-group protections remain unconfirmed.

Primary frameworkLaw n° 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberA non-binding awareness initiative is confirmed; statutory child/vulnerable-group protections remain unconfirmed.

Sub-modules (5)

Age VerificationRed

No T1/T2 source on statutory age-verification requirements under Moroccan law located.

Absence provenance: No age-verification provision confirmed.. Searched: CNDP Maroc protection données personnelles 2026.

Minor Profiling BansRed

No T1/T2 source on minor-profiling bans under Moroccan law located.

Absence provenance: No minor-profiling ban confirmed.. Searched: CNDP Maroc protection données personnelles 2026.

Education SettingsAmber

CNDP's 'Koun3labal' platform provides digital-privacy awareness content for children, adolescents, parents, guardians and teachers.

Claims (1):

  • CNDP launched the 'Koun3labal' platform to raise awareness among children, adolescents, parents, guardians and teachers regarding digital privacy opportunities, dangers, rights and remedies.

Dependent AdultsRed

No T1/T2 source on dependent-adult data-protection safeguards under Moroccan law located.

Absence provenance: No dependent-adult protection confirmed.. Searched: CNDP Maroc protection données personnelles 2026.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative37 words

CNDP launched the 'Koun3labal' awareness platform targeting children, adolescents, parents, guardians and teachers on digital-privacy rights and risks. No T1/T2 source confirming statutory age-of-consent thresholds, parental-consent mechanisms, minor-profiling bans, or dependent-adult protections under Law 09-08 was located.

Sources and claims (1)
  1. ConfirmedIAPPCNDP launched the 'Koun3labal' platform to raise awareness among children, adolescents, parents, guardians and teachers regarding digital privacy opportunities, dangers, rights and remedies.observed

#

Enforcement cooperation architecture and a recent 180-day development are confirmed; funding/capacity and redress-mechanism sub-modules remain unconfirmed.

Primary frameworkLaw n° 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberEnforcement cooperation architecture and a recent 180-day development are confirmed; funding/capacity and redress-mechanism sub-modules remain unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The 2018 gap analysis identified limits on the powers granted to the CNDP as a divergence from GDPR-equivalent supervisory-authority powers.

Claims (1):

  • The 2018 gap analysis identified limits on the powers granted to the CNDP as a divergence from GDPR-equivalent supervisory-authority powers.

Enforcement Activity IndexAmber

CNDP established a collaborative enforcement roadmap with the Public Ministry (2019) and participated in a 2023 multi-authority international joint statement.

Claims (2):

  • CNDP and Morocco's Public Ministry agreed a collaborative roadmap, including a case-tracking system and a dedicated prosecution unit, to enforce Law 09-08.
  • CNDP was among twelve data-protection authorities from six continents that jointly issued an August 2023 statement to major social-media companies regarding data-scraping and children's-privacy expectations.

Regulator Funding And CapacityRed

No T1/T2 source on CNDP funding or headcount was located.

Absence provenance: No funding/capacity data confirmed.. Searched: Morocco CNDP fine sanction 2025 2026 enforcement.

Collective Redress And Class ActionsRed

No T1/T2 source on collective-redress mechanisms under Moroccan law was located.

Absence provenance: No collective-redress mechanism confirmed.. Searched: Morocco CNDP fine sanction 2025 2026 enforcement.

Private Right Of ActionRed

No T1/T2 source on a private right of action under Moroccan law was located.

Absence provenance: No private-right-of-action provision confirmed.. Searched: Morocco law 09-08 criminal penalties fines article CNDP sanctions imprisonment.

Recent Developments 180DAmber

Within the last 180 days, CNDP presented recommendations on genomic/genetic data processing (May 2026).

Claims (1):

  • Within the last 180 days, CNDP presented recommendations concerning the processing of genomic/genetic data.

Key findings (3)

  • — source on file
  • — source on file
  • — source on file
Category narrative68 words

The 2018 gap analysis identified limits on CNDP's powers relative to GDPR-equivalent supervisory authorities. CNDP and Morocco's Public Ministry established a collaborative enforcement roadmap including a case-tracking system and dedicated prosecution unit (2019). CNDP participated in a 2023 multi-authority joint statement on social-media data practices. Recent development: CNDP presented genomic-data recommendations (May 2026). No T1/T2 source on regulator funding/capacity, collective redress, or private right of action was located.

Sources and claims (4)
  1. ProbableIAPPThe 2018 gap analysis identified limits on the powers granted to the CNDP as a divergence from GDPR-equivalent supervisory-authority powers.observed
  2. ConfirmedDataGuidanceCNDP and Morocco's Public Ministry agreed a collaborative roadmap, including a case-tracking system and a dedicated prosecution unit, to enforce Law 09-08.observed
  3. ConfirmedOPC CanadaCNDP was among twelve data-protection authorities from six continents that jointly issued an August 2023 statement to major social-media companies regarding data-scraping and children's-privacy expectations.observed
  4. UncertainDataGuidanceWithin the last 180 days, CNDP presented recommendations concerning the processing of genomic/genetic data.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Macau SAR
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 26 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, cross_border_and_adequacy, and enforcement_and_redress modules achieved the strongest coverage, anchored primarily on T2 IAPP/DataGuidance secondary analysis of Law n° 09-08 plus a T3 OPC Canada compilation confirming Morocco's Convention 108 accession and GPA joint-statement participation. lawful_processing_and_special_data, data_subject_rights, and controller_processor_duties relied heavily on a single 2018 CNDP/EU gap-analysis source (SRC-MO-01) documenting specific statutory gaps (no right to be forgotten, no portability, no breach-notification duty, no biometric/sexual-orientation special categories). algorithmic_biometric_and_surveillance_governance, adtech_and_commercial_privacy, and children_and_vulnerable_groups rely on title-only/paywalled DataGuidance and IAPP news items (facial recognition deliberation, genomic data recommendations, direct-marketing FAQs, Koun3labal platform) where full substantive text could not be retrieved, and confidence was accordingly downgraded to Uncertain. sectoral_watch returned no findings across all seven sub-modules and is emitted with explicit absent_field_provenance rather than fabricated obligations. No T1 (official CNDP or Bulletin Officiel) full-text instrument was directly retrieved in this run; all claims trace to T2/T3 secondary sources.

Unresolved questions (5):

  • Has Law n° 09-08 been formally amended or replaced since the 2018 gap-analysis scenarios were studied, and if so, which of the identified gaps (consent validity, breach notification, biometric/sexual-orientation categories, erasure, portability, CNDP powers) have been remedied?
  • Is Morocco's 2009 EU adequacy request still formally pending as of 2026, or has it been withdrawn, superseded, or resolved?
  • What are the specific DPO appointment thresholds, security-measure requirements, and retention/disposal duties (if any) under Law 09-08 or its Implementation Decree?
  • What is the substantive content of the CNDP DPIA decision, facial-recognition deliberation, genomic-data recommendations, and direct-marketing FAQs, which were only accessible at headline level in this run?
  • Are there sector-specific data-protection overlays (financial, health, telecoms, employment, credit, education, insurance) in Morocco that supplement or displace Law 09-08?

Escalate to primary-source review: yes