🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
MA · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 11 sources retrieved model claude-sonnet-5 ·

Morocco

MA schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 26 claims · 11 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
26Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus law and operational regulator exist, but gap-analysis-identified limits on CNDP powers and unconfirmed territorial scope pull the rating down from green.

Primary frameworkLaw No. 09-08 of 18 February 2009 on the Protection of Individuals with regard to the Processing of Personal Data, and Implementing Decree No. 2-09-165 of 21 May 2009
Traffic-light rationale — AmberComprehensive omnibus law and operational regulator exist, but gap-analysis-identified limits on CNDP powers and unconfirmed territorial scope pull the rating down from green.

Sub-modules (5)

Regulator And AuthorityGreen

CNDP is the designated national supervisory authority under Law 09-08.

Claims: CLM-MA-a0000001

Act And InstrumentsAmber

Primary instrument is Law 09-08 plus its 2009 implementing decree; CNDP has periodically announced reform/modernisation plans.

Claims: CLM-MA-a0000002, CLM-MA-a0000003

Material ScopeGreen

Gap analysis found material scope broadly convergent with GDPR definitions and principles.

Claims: CLM-MA-a0000004

Territorial ScopeAmber

No sourced evidence located on extraterritorial application to non-established controllers; searched 'Law 09-08 territorial scope non-established controllers' without a confirmed dedicated provision.

Claims: CLM-MA-c48f2e91, CLM-MA-c48f2e91, CLM-MA-c48f2e91

Regulator Registration And FilingAmber

CNDP opened a national data-protection register/filing platform for controllers.

Claims: CLM-MA-a0000005

Category narrative69 words

Morocco's data protection regime rests on Law n° 09-08 of 18 February 2009 and its Implementing Decree n° 2-09-165 of 21 May 2009, supervised by the CNDP. A 2018 Morocco-EU gap-analysis study found convergence with the GDPR on definitions, material scope and processing principles, but flagged limits on CNDP's powers. No sourced evidence was found on express extraterritorial/non-established-controller scope; searched 'CNDP territorial scope non-established controllers' yielded no dedicated provision.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP) is Morocco's national data protection supervisory authority responsible for overseeing compliance with Law No. 09-08.
  2. ConfirmedIAPPPersonal data protection in Morocco is governed by Law n° 09-08 of 18 February 2009 relating to the protection of individuals with respect to the processing of personal data, and its Implementation Decree n° 2-09-165 of 21 May 2009.
  3. ConfirmedDataGuidanceIn March 2020, CNDP announced measures including plans to revise national data protection laws and promote privacy-by-design, alongside internal reorganisation to speed up processing of notifications.
  4. ProbableIAPPA Morocco-EU gap-analysis study found convergence between Law 09-08 and the GDPR on definitions, material scope of the law, and the principles of data processing.
  5. ProbableIAPPCNDP opened a national data protection register for controller filings/notifications.

#

Core principles exist but consent standards and special-category coverage materially diverge from GDPR-equivalent baselines.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberCore principles exist but consent standards and special-category coverage materially diverge from GDPR-equivalent baselines.

Sub-modules (4)

Lawful BasesAmber

Gap analysis found convergence on general processing principles, though not a GDPR Article-6-style enumerated lawful-bases list.

Claims: CLM-MA-a0000006

Special CategoriesRed

Law 09-08 does not reference biometric data or sexual orientation as special categories.

Claims: CLM-MA-a0000008

Pseudonymisation And AnonymisationRed

No sourced provisions found; searched 'Morocco 09-08 pseudonymisation anonymisation safe harbour' without result.

Category narrative50 words

Law 09-08's general processing principles were found broadly convergent with GDPR principles, but the same gap analysis identified material divergences: no detailed consent-validity conditions, and no biometric data or sexual-orientation categories among protected special categories. No sourced information was located on pseudonymisation/anonymisation safe-harbours; searched 'Law 09-08 pseudonymisation anonymisation' without result.

Sources and claims (3)
  1. ProbableIAPPA Morocco-EU gap analysis found convergence between Law 09-08 and the GDPR on the general principles of data processing, though without a GDPR Article-6-style enumerated list of lawful bases.
  2. ConfirmedIAPPThe Morocco-EU gap analysis found that Law 09-08 has no detailed conditions related to the validity of consent, unlike the GDPR's requirements for freely given, specific and informed consent.
  3. ConfirmedIAPPThe gap analysis identified the absence of references to biometric data or sexual orientation as protected special categories under Law 09-08, diverging from the GDPR's Article 9 special-category regime.

#

Core rights (access, rectification, objection) exist; erasure and portability are absent, and statutory deadlines are unconfirmed.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberCore rights (access, rectification, objection) exist; erasure and portability are absent, and statutory deadlines are unconfirmed.

Sub-modules (5)

Access RightAmber

Inferred as convergent with GDPR baseline since the gap analysis did not flag access rights as a divergence.

Claims: CLM-MA-a0000009

Rectification And ErasureAmber

Rectification inferred as convergent; erasure/right-to-be-forgotten confirmed absent.

Claims: CLM-MA-a0000009, CLM-MA-a000000b

Restriction And ObjectionAmber

Objection right inferred as convergent since not flagged as a divergence area.

Claims: CLM-MA-a0000009

Data PortabilityRed

Data portability confirmed absent under Law 09-08.

Claims: CLM-MA-a000000a

Deadlines And Response WindowsRed

No sourced statutory response-window data found; searched 'CNDP data subject request deadline days' without result.

Category narrative71 words

Because the Morocco-EU gap analysis singled out only the absence of a right to be forgotten and a right to data portability as divergences in data subject rights, this indicates that access, rectification and objection rights under Law 09-08 are broadly convergent with the GDPR baseline; erasure and portability are confirmed gaps. No sourced information was found on statutory response-window deadlines; searched 'Law 09-08 CNDP subject access request deadline' without result.

Sources and claims (3)
  1. ProbableIAPPBecause the Morocco-EU gap analysis identified only the absence of a right to be forgotten and a right to data portability as divergences in data subject rights, rights of access, rectification and objection under Law 09-08 are inferred to be broadly convergent with the GDPR baseline.
  2. ConfirmedIAPPLaw 09-08 does not provide data subjects a right to data portability, a gap identified relative to the GDPR.
  3. ConfirmedIAPPLaw 09-08 does not include a right to be forgotten/erasure right equivalent to GDPR Article 17.

#

Some accountability practice (DPIA guidance, breach-handling reminders) exists but core GDPR-equivalent duties (DPO, ROPA, retention) are unconfirmed or absent.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberSome accountability practice (DPIA guidance, breach-handling reminders) exists but core GDPR-equivalent duties (DPO, ROPA, retention) are unconfirmed or absent.

Sub-modules (7)

Accountability And DpiaAmber

CNDP published a decision setting DPIA-type assessment criteria.

Claims: CLM-MA-a000000c

Dpo RequirementsRed

No sourced evidence of a statutory DPO appointment threshold; searched 'Morocco 09-08 DPO requirement' without result.

Ropa RequirementsRed

No sourced ROPA/records-of-processing requirement found; searched 'CNDP registre des traitements' without result.

Joint Controller ArrangementsRed

No sourced joint-controller provisions found.

Security MeasuresRed

No sourced technical/organisational security-measure specifics found.

Breach NotificationAmber

Gap analysis found no codified breach-notification duty; CNDP has nonetheless issued practical reminders to controllers on breach procedure.

Claims: CLM-MA-a000000d, CLM-MA-a000000e

Retention And DisposalRed

No sourced retention/disposal limits found; searched 'Law 09-08 data retention limits' without result.

Category narrative75 words

CNDP has published a decision setting criteria for DPIA-type assessments and has issued reminders to controllers on data-breach handling procedures, notwithstanding the gap analysis finding that Law 09-08 imposes no codified statutory breach-notification duty to the regulator. No sourced evidence was found on DPO appointment thresholds, ROPA requirements, joint-controller arrangements, technical/organisational security-measure specifics, or retention/disposal limits; searched 'Law 09-08 DPO requirement', 'CNDP ROPA registre des traitements', and 'Law 09-08 data retention limits' without confirmed results.

Sources and claims (3)
  1. ProbableDataGuidanceCNDP has published a decision setting out criteria for when a Data Protection Impact Assessment-type assessment is required for certain processing operations.
  2. ConfirmedIAPPThe Morocco-EU gap analysis found that Law 09-08 lacks a requirement to notify the supervisory authority of personal data breaches, a divergence from the GDPR's Articles 33-34 breach-notification regime.
  3. ProbableDataGuidanceCNDP has issued reminders to controllers regarding data-breach handling procedures notwithstanding the absence of a codified statutory breach-notification obligation.

#

A transfer mechanism and authorisation process exist, but EU adequacy remains unresolved and SCC/BCR/localisation instruments are unconfirmed.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberA transfer mechanism and authorisation process exist, but EU adequacy remains unresolved and SCC/BCR/localisation instruments are unconfirmed.

Sub-modules (6)

Transfer MechanismsAmber

Trans-border transfer principles found convergent with GDPR; CNDP operates an expedited transfer-authorisation process.

Claims: CLM-MA-a0000010, CLM-MA-a0000011

Adequacy ReceivedAmber

Morocco's 2009 EU adequacy request remains pending as of the most recent reported review.

Claims: CLM-MA-a000000f

Adequacy GrantedRed

No sourced evidence Morocco has granted adequacy status to other regimes; searched 'Morocco adequacy decision granted third country' without result.

Sccs And BcrsRed

No sourced SCC/BCR framework found under Moroccan law.

Transfer Impact AssessmentRed

No sourced TIA requirement found.

Data LocalisationRed

No sourced data-localisation mandate found.

Category narrative79 words

Law 09-08's principles applicable to trans-border data transfers were found convergent with the GDPR approach, and CNDP has approved an expedited authorisation process for certain transfers. Morocco requested EU adequacy recognition as early as 2009 and this request remains reported as pending. No sourced evidence was found on SCC/BCR forms, transfer-impact-assessment requirements, data-localisation mandates, or adequacy decisions granted by Morocco to other regimes; searched 'CNDP SCC BCR', 'Morocco data localisation law', and 'Morocco adequacy decision granted' without confirmed results.

Sources and claims (3)
  1. ConfirmedIAPPMorocco requested an EU adequacy recognition decision as early as 2009, and this request remains reported as pending.
  2. ProbableIAPPLaw 09-08's principles applicable to trans-border data transfers were found to converge with the GDPR's approach in a Morocco-EU gap analysis.
  3. ProbableDataGuidanceCNDP approved an expedited process to authorise certain cross-border personal data transfers.

#

Only one sub-module (health, via genomic-data recommendations) has sourced evidence; the remaining six sub-modules carry no confirmed sectoral overlay.

Supervisory authorityCNDP
Traffic-light rationale — RedOnly one sub-module (health, via genomic-data recommendations) has sourced evidence; the remaining six sub-modules carry no confirmed sectoral overlay.

Sub-modules (7)

Financial Sector OverlayRed

No sourced financial-sector DP overlay found; searched 'CNDP secteur bancaire données personnelles' without result.

Health Sector OverlayAmber

CNDP has presented recommendations specifically addressing genomic data processing.

Claims: CLM-MA-a0000012

Telecoms And EprivacyRed

No sourced telecoms/ePrivacy-equivalent regime found; searched 'Morocco telecoms ePrivacy cookies law' without result.

Employment DataRed

No sourced employment-data-specific rules found.

Credit And ScoringRed

No sourced credit-scoring rules found.

EducationRed

No sourced education-sector-specific DP rules found beyond general awareness initiatives.

InsuranceRed

No sourced insurance-sector DP rules found.

Category narrative62 words

Sourced sectoral evidence is limited to CNDP recommendations on genomic/genetic data processing (health sector). No sourced overlays were found for financial services, telecoms/ePrivacy, employment, credit-scoring, education, or insurance sectors; searched 'CNDP secteur bancaire données personnelles', 'Morocco telecoms ePrivacy cookies law', 'CNDP employment data guidance', 'Morocco credit scoring data protection', 'CNDP education sector data', and 'Morocco insurance sector data protection' without confirmed results.

Sources and claims (1)
  1. ProbableDataGuidanceCNDP has presented recommendations specifically addressing the processing of genomic data.

#

No comprehensive or sector-specific adtech/commercial-privacy regime was identified for this JID beyond the general data protection law.

Traffic-light rationale — RedNo comprehensive or sector-specific adtech/commercial-privacy regime was identified for this JID beyond the general data protection law.

Sub-modules (6)

Cookies And TrackersRed

No sourced cookie/tracker-specific consent regime found.

Dark PatternsRed

No sourced dark-pattern prohibition found.

Opt Out SignalsRed

No sourced recognition of opt-out signals (e.g., GPC/DAA) found.

Clean Rooms And DcrRed

No sourced clean-room/data-collaboration-room rules found.

Cross Context AdvertisingRed

No sourced cross-context-advertising-specific regime found.

Direct MarketingRed

No sourced direct-marketing consent/suppression regime distinct from general law found.

Category narrative58 words

No sourced evidence was found of a Moroccan cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition (e.g. GPC), clean-room/data-collaboration rules, cross-context-advertising regime, or direct-marketing consent/suppression framework distinct from the general provisions of Law 09-08. Searched 'Morocco cookie law consent', 'CNDP dark patterns', 'Morocco Global Privacy Control', 'CNDP direct marketing opt-out', and 'Morocco data clean room regulation' without confirmed results.

#

Biometric data is confirmed excluded from special-category protection and most sub-modules (profiling, ADM transparency, AI risk assessment, surveillance carve-outs) carry no sourced findings.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — RedBiometric data is confirmed excluded from special-category protection and most sub-modules (profiling, ADM transparency, AI risk assessment, surveillance carve-outs) carry no sourced findings.

Sub-modules (6)

Profiling RestrictionsRed

No sourced profiling-restriction provisions found; searched 'Law 09-08 profiling restrictions' without result.

Automated Decision Making TransparencyRed

No sourced ADM transparency/explanation-right provisions found.

Ai Risk AssessmentsRed

No sourced AI-specific risk-assessment regime found.

Biometric RegimeRed

Biometric data is confirmed absent from Law 09-08's special-category definitions.

Claims: CLM-MA-a0000013

Genetic DataAmber

CNDP has issued recommendations on genomic data despite no dedicated statutory genetic-data category.

Claims: CLM-MA-a0000014

State Surveillance CarveoutsRed

No sourced state-surveillance carve-out provisions found; searched 'Law 09-08 national security exemption' without result.

Category narrative72 words

The Morocco-EU gap analysis found that Law 09-08 does not include biometric data within its special-category definitions, and CNDP has issued recommendations on genomic/genetic data despite no dedicated statutory genetic-data category. No sourced evidence was found on profiling restrictions, automated-decision-making transparency/explanation rights, AI-specific risk assessments, or state-surveillance carve-outs; searched 'Law 09-08 profiling restrictions', 'Morocco automated decision making transparency', 'Morocco AI Act risk assessment', and 'Law 09-08 national security exemption' without confirmed results.

Sources and claims (2)
  1. ConfirmedIAPPThe Morocco-EU gap analysis found that Law 09-08 does not include biometric data within its special-category definitions, unlike GDPR Article 9.
  2. ProbableDataGuidanceCNDP has issued recommendations concerning genomic data processing, indicating regulatory attention to genetic data despite the absence of a dedicated statutory genetic-data category in Law 09-08.

#

Only an awareness/education initiative is sourced; no statutory age-verification, parental-consent, minor-profiling-ban, or dependent-adult provisions were confirmed.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — RedOnly an awareness/education initiative is sourced; no statutory age-verification, parental-consent, minor-profiling-ban, or dependent-adult provisions were confirmed.

Sub-modules (5)

Age VerificationRed

No sourced statutory age-of-consent/age-verification mechanism found.

Minor Profiling BansRed

No sourced minor-profiling-ban provisions found.

Education SettingsAmber

CNDP launched an awareness platform for children, parents, guardians and teachers on digital privacy.

Claims: CLM-MA-a0000015

Dependent AdultsRed

No sourced dependent-adult protection provisions found; searched 'CNDP dependent adults data protection' without result.

Category narrative62 words

No statutory age-of-consent, parental-consent mechanism, or minor-profiling ban was found under Law 09-08. CNDP has, however, launched an awareness platform ('Koun3labal') targeting children, adolescents, parents, guardians and teachers on digital privacy risks and rights. No sourced evidence was found on dependent-adult protections; searched 'Morocco age of digital consent minors', 'Law 09-08 parental consent', and 'CNDP dependent adults data protection' without confirmed results.

Sources and claims (1)
  1. ConfirmedIAPPCNDP launched the 'Koun3labal' platform to raise awareness among children, adolescents, parents, guardians and teachers about digital privacy opportunities, dangers, risks, rights and remedies.

#

Institutional enforcement cooperation and international engagement exist, but CNDP's statutory powers are reportedly limited and collective-redress/private-right-of-action mechanisms are unconfirmed.

Primary frameworkLaw No. 09-08 of 18 February 2009
Supervisory authorityCNDP
Traffic-light rationale — AmberInstitutional enforcement cooperation and international engagement exist, but CNDP's statutory powers are reportedly limited and collective-redress/private-right-of-action mechanisms are unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Gap analysis found limits on CNDP's statutory powers; CNDP participates in international regulatory cooperation.

Claims: CLM-MA-a0000016, CLM-MA-a0000018

Enforcement Activity IndexAmber

CNDP and the Public Ministry agreed a collaborative enforcement roadmap in January 2019.

Claims: CLM-MA-a0000017

Regulator Funding And CapacityRed

Commentary (opinion-tier source) describes limited enforcement resources.

Claims: CLM-MA-a000001a

Collective Redress And Class ActionsRed

No sourced collective-redress/class-action mechanism found; searched 'Morocco data protection class action' without result.

Private Right Of ActionRed

No sourced private right of action for data subjects found.

Recent Developments 180DAmber

Most recent (within ~180 days of run date) reported CNDP regulatory activity is the May 2026 genomic-data recommendations.

Claims: CLM-MA-a0000019

Category narrative104 words

The Morocco-EU gap analysis identified limits on the powers granted to CNDP as a divergence from the GDPR enforcement framework. CNDP nonetheless reached a January 2019 agreement with Morocco's Public Ministry establishing a case-tracking system and a dedicated prosecution unit for CNDP-referred cases, and was among 12 authorities that signed an August 2023 joint statement to major social-media companies. Commentary characterises the regime as facing limited enforcement resources. No sourced evidence was found on collective-redress/class-action mechanisms or a private right of action for data subjects; searched 'Morocco data protection class action', 'CNDP private right of action court', and 'CNDP budget headcount' without confirmed results.

Sources and claims (5)
  1. ConfirmedIAPPThe Morocco-EU gap analysis identified limits on the powers granted to CNDP as an area of divergence from the GDPR's enforcement framework for supervisory authorities.
  2. ConfirmedDataGuidanceCNDP and Morocco's Public Ministry agreed in January 2019 on a collaborative roadmap including a case-tracking system and a dedicated prosecution unit for data-protection cases referred by CNDP.
  3. ConfirmedOffice of the Privacy Commissioner of CanadaCNDP was among 12 data protection authorities from six continents that signed a joint statement addressed to major social media companies in August 2023.
  4. ProbableDataGuidanceIn May 2026, CNDP presented recommendations on the processing of genomic data, representing the most recently reported CNDP regulatory guidance activity within the evaluation window.
  5. UncertainIAPPCommentary characterises Law 09-08 as championing fair and lawful data processing while facing ambiguous definitions and limited enforcement resources.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Morocco
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 26 claim(s), 11 source(s) in the cumulative register.