HomeResources › Data protection (CNDP)

Guide · 9 min read

Data protection (CNDP) — Loi 09-08 for Moroccan SMEs

Loi 09-08 is Morocco’s personal-data protection regime, broadly inspired by the EU’s pre-GDPR Directive 95/46. Compliance is enforced by the CNDP (Commission Nationale de contrôle de la Protection des Données à caractère Personnel). This guide reduces the law to what an Agadir SaaS, marketplace or e-commerce founder must do this month.

Does Loi 09-08 apply to you?

Yes if your start-up does any of the following:

The four CNDP regimes

RegimeWhenProcess
Déclaration normaleMost ordinary processing (CRM, payroll, marketing).Online form via cndp.ma; tacit approval after 2 months.
Déclaration simplifiéePre-approved standard processing (HR, customer file).Same form, faster review.
Demande d’autorisationSensitive data (health, biometric, judicial), CCTV, scoring, automated decisioning.Express CNDP authorisation required before processing starts.
Transfert internationalAny transfer of personal data outside Morocco.CNDP authorisation; Standard Contractual Clauses (SCCs) attached.

The 8 principles you must respect

  1. Lawful basis — consent, contract, legal obligation, legitimate interest.
  2. Purpose limitation — stated purpose at collection.
  3. Data minimisation — collect only what you need.
  4. Accuracy — keep data correct and up-to-date.
  5. Retention limit — define and respect retention periods.
  6. Security — appropriate technical and organisational measures.
  7. Confidentiality — by employees and processors.
  8. Subject rights — access, rectification, opposition.

What to publish on your site or app

Cross-border transfers — the trap

Most Moroccan SaaS use AWS, Google Cloud, Azure, Stripe, HubSpot or SendGrid — all of which involve transferring personal data outside Morocco. Without CNDP authorisation, these transfers are illegal.

  1. Identify each processor and where data sits (region of cloud).
  2. Sign the standard Contrat de Sous-Traitance with each.
  3. Add Standard Contractual Clauses for transfers outside Morocco.
  4. File a single demande d’autorisation transferts hors du Maroc covering all processors.
  5. Renew when you add a new processor.

Penalties

30-day starter plan

  1. Day 1–3: Map all data flows (customer, employee, supplier, marketing).
  2. Day 4–7: Identify lawful basis for each processing activity.
  3. Day 8–10: Draft / refresh privacy policy + cookie banner.
  4. Day 11–15: Sign processor contracts (DPA + SCCs).
  5. Day 16–22: File CNDP declarations and the cross-border authorisation request.
  6. Day 23–30: Train your team. Appoint a Correspondant Loi 09-08.

Looking ahead — a Moroccan GDPR?

The CNDP has signalled a major reform of Loi 09-08 to align with the EU GDPR (data-protection officers, breach notification within 72 hours, accountability principle). Draft expected 2026–2027. Build your compliance posture as if GDPR-equivalent — it is the path of least retro-fit.

Open CNDP ↗ Employee data & payroll → Protect your IP →