Home › Resources › Data protection (CNDP)
Guide · 9 min readData protection (CNDP) — Loi 09-08 for Moroccan SMEs
Loi 09-08 is Morocco’s personal-data protection regime, broadly inspired by the EU’s pre-GDPR Directive 95/46. Compliance is enforced by the CNDP (Commission Nationale de contrôle de la Protection des Données à caractère Personnel). This guide reduces the law to what an Agadir SaaS, marketplace or e-commerce founder must do this month.
Does Loi 09-08 apply to you?
Yes if your start-up does any of the following:
- Holds an email or phone list of customers, leads or job applicants.
- Runs a website, app or SaaS that creates user accounts.
- Operates CCTV in a workplace or public space.
- Processes employee payroll, CNSS or AMO data.
- Uses location data, biometric data or health data.
- Transfers any personal data outside Morocco (e.g. AWS Frankfurt, Stripe US, HubSpot EU).
The four CNDP regimes
| Regime | When | Process |
|---|---|---|
| Déclaration normale | Most ordinary processing (CRM, payroll, marketing). | Online form via cndp.ma; tacit approval after 2 months. |
| Déclaration simplifiée | Pre-approved standard processing (HR, customer file). | Same form, faster review. |
| Demande d’autorisation | Sensitive data (health, biometric, judicial), CCTV, scoring, automated decisioning. | Express CNDP authorisation required before processing starts. |
| Transfert international | Any transfer of personal data outside Morocco. | CNDP authorisation; Standard Contractual Clauses (SCCs) attached. |
The 8 principles you must respect
- Lawful basis — consent, contract, legal obligation, legitimate interest.
- Purpose limitation — stated purpose at collection.
- Data minimisation — collect only what you need.
- Accuracy — keep data correct and up-to-date.
- Retention limit — define and respect retention periods.
- Security — appropriate technical and organisational measures.
- Confidentiality — by employees and processors.
- Subject rights — access, rectification, opposition.
What to publish on your site or app
- Privacy policy in French + Arabic (English optional).
- Cookie banner with granular consent.
- Terms of service.
- CNDP authorisation reference number on the privacy page.
- Clear contact for data subject rights.
Cross-border transfers — the trap
Most Moroccan SaaS use AWS, Google Cloud, Azure, Stripe, HubSpot or SendGrid — all of which involve transferring personal data outside Morocco. Without CNDP authorisation, these transfers are illegal.
- Identify each processor and where data sits (region of cloud).
- Sign the standard Contrat de Sous-Traitance with each.
- Add Standard Contractual Clauses for transfers outside Morocco.
- File a single demande d’autorisation transferts hors du Maroc covering all processors.
- Renew when you add a new processor.
Penalties
- Failure to declare: fine up to MAD 200 000.
- Unauthorised transfer outside Morocco: fine up to MAD 300 000 + criminal liability.
- Sensitive data processing without authorisation: imprisonment 3 months – 1 year + fine MAD 20 000–200 000.
30-day starter plan
- Day 1–3: Map all data flows (customer, employee, supplier, marketing).
- Day 4–7: Identify lawful basis for each processing activity.
- Day 8–10: Draft / refresh privacy policy + cookie banner.
- Day 11–15: Sign processor contracts (DPA + SCCs).
- Day 16–22: File CNDP declarations and the cross-border authorisation request.
- Day 23–30: Train your team. Appoint a Correspondant Loi 09-08.
Looking ahead — a Moroccan GDPR?
The CNDP has signalled a major reform of Loi 09-08 to align with the EU GDPR (data-protection officers, breach notification within 72 hours, accountability principle). Draft expected 2026–2027. Build your compliance posture as if GDPR-equivalent — it is the path of least retro-fit.