Skip to the content
Global Data RulesData governance rules, country by country

Compare countries

Two or three countries, side by side, one row per question. Pick up to 3.

Countries
MoroccoChecked 18 August 2026
Depends on your industryWork: HighEnforcement: Waking up
In one paragraph
Morocco lets personal data leave the country, but only to 32 approved countries, or with case-by-case permission from the privacy regulator. The United States is not on the approved list. Government bodies, and companies the state has quietly labelled "vital", must keep their sensitive data on Moroccan soil. Sending it abroad is a crime, not just a fine.
The catch
The paperwork route works for ordinary business data. It does not exist at all for two groups: public bodies, and private companies designated as vital infrastructure. Their sensitive data must be hosted only in Morocco. Since August 2025 their sensitive cloud work must also sit with a cloud provider licensed by the national cyber authority, and the published list of licensed providers is still empty. Banking, telecoms and health each add their own layer on top.
Does this apply to me?
The privacy law reaches you in two situations. First, if you run any operation in Morocco, whatever its legal form. Second, if you have no office in Morocco but use equipment there to handle people's data. Just having Moroccan customers, with everything running abroad, is not by itself enough. If the equipment test catches you, you must give the regulator the name of a representative based in Morocco, and that person takes on your legal duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
It depends who you are. For ordinary business, data may leave only to a country on the regulator's approved list, or with that regulator's written permission. The approved list has 32 countries: the European Union states except Croatia, plus Britain, Switzerland, Norway, Iceland, Liechtenstein and Canada. The United States is not on it. For public bodies and for companies designated as vital infrastructure, sensitive data cannot leave at all: the cyber security law says it must be hosted only on Moroccan territory, and doing otherwise is a criminal offence.High confidence
What do I have to do to send it abroad?
The model is an approved list, and the list is real and populated with 32 countries. If your destination is on it, you still file a transfer notice with the regulator, but you need no separate permission. If it is not on it, you need written permission, applied for on the regulator's transfer form. The regulator answers within two months, and can extend that once. You cannot get transfer permission before the underlying use of the data has itself been declared or authorised. Narrow escape routes exist, such as the person's clear consent, or a transfer needed to perform a contract or to save someone's life.High confidence
Who enforces this — and are they actually working?
Two regulators matter, and both are real. The privacy regulator is the National Commission for the Control of Personal Data Protection. It has a chairman who has been in post since November 2018 and six members appointed in January 2025, and it was still issuing decisions in late 2025 and signing agreements in 2026. The cyber regulator is the General Directorate for Information Systems Security, part of national defence administration. It issues binding licences to security auditors, runs the national incident team and investigated the 2025 data leaks. Neither publishes a stream of fines: the privacy law's penalties are criminal, so a court has to impose them.Medium confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and they come from different laws. The ceiling is general: personal data may be kept only in a form that identifies people for as long as the purpose needs, and no longer. The floors are sector rules. Banks must keep the documents behind a customer's account for ten years. Payment institutions must keep a register of payment transactions for at least ten years. Telecoms operators, internet access providers, digital service providers and platform publishers must keep connection data, computer logs and security-event records for one year.Medium confidence
What happens when something goes wrong?
Count two clocks, and notice that one of them is missing. Public bodies, vital infrastructures, telecoms operators, internet access providers, digital service providers and platform publishers must report a cyber incident to the national cyber agency as soon as they know about it. The agency asks for it immediately, by a standard form sent to its incident team, with no fixed number of hours in the law. The missing clock is the privacy one: the 2009 privacy law contains no general duty to report a personal data breach to the regulator or to the people affected.High confidence
What's the trap?
Five things that cost people their weekend. First, the United States is not an approved destination, so ordinary use of a big American cloud needs case-by-case permission, and Croatia is missing from the list while Britain is still on it. Second, the list of companies designated as vital infrastructure is kept secret by law, so you can be inside the strictest regime and only find out privately. Third, the penalties are criminal: up to one year in prison for a person, and fines doubled for a company. Fourth, a foreign company using equipment in Morocco must name a representative based there who inherits its obligations. Fifth, the top level of cloud licence requires Moroccan majority ownership and Moroccan staff, so a global cloud provider cannot qualify without a waiver signed off by the head of government.High confidence
What's about to change?
One hard date and several switches. The hard date is 21 August 2027: public bodies and vital infrastructures that were already using cloud services for sensitive systems or sensitive data must by then have moved to a provider licensed by the national cyber authority. Today no provider holds that licence, so everyone is relying on the temporary rule that lets you keep an unlicensed provider while none is available. The moment the first licence is granted, the duty to migrate starts to bite in practice. We found no bill to replace the 2009 privacy law on official sources, checked on 18 August 2026.High confidence
Hardest industry wall
  • Government Loi n° 05-20 relative à la cybersécurité
  • Government Décret n° 2-24-921 relatif au recours aux prestataires de services Cloud par les entités et les infrastructures d'importance vitale disposant de systèmes d'information ou de données sensibles
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
In one paragraph
Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
The catch
The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
Does this apply to me?
Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
Can the data leave the country?
Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
What do I have to do to send it abroad?
The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
Who enforces this — and are they actually working?
The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
How long must I keep it, and when must I delete it?
There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
What happens when something goes wrong?
There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
What's the trap?
Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
What's about to change?
Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
Hardest industry wall
  • Telecoms Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
  • E-commerce Loi n° 18-05 relative au commerce electronique
  • Government Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees