Skip to the content
Global Data RulesData governance rules, country by country

Morocco

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Waking up

Morocco lets personal data leave the country, but only to 32 approved countries, or with case-by-case permission from the privacy regulator. The United States is not on the approved list. Government bodies, and companies the state has quietly labelled "vital", must keep their sensitive data on Moroccan soil. Sending it abroad is a crime, not just a fine.

Data governance in Morocco

The eight things that decide how you handle data about people in Morocco. Same eight on every country page, so you can compare.

Who has to follow these rules

The privacy law reaches you in two situations. First, if you run any operation in Morocco, whatever its legal form. Second, if you have no office in Morocco but use equipment there to handle people's data. Just having Moroccan customers, with everything running abroad, is not by itself enough. If the equipment test catches you, you must give the regulator the name of a representative based in Morocco, and that person takes on your legal duties. There is no size or revenue threshold to fall below.

High confidenceNational rulesAppoint a local representativeRegister or notify

Where the data is allowed to live

It depends who you are. For ordinary business, data may leave only to a country on the regulator's approved list, or with that regulator's written permission. The approved list has 32 countries: the European Union states except Croatia, plus Britain, Switzerland, Norway, Iceland, Liechtenstein and Canada. The United States is not on it. For public bodies and for companies designated as vital infrastructure, sensitive data cannot leave at all: the cyber security law says it must be hosted only on Moroccan territory, and doing otherwise is a criminal offence.

High confidenceDepends on your industryAllowlistKeep the data in the country

Sending data out of the country

The model is an approved list, and the list is real and populated with 32 countries. If your destination is on it, you still file a transfer notice with the regulator, but you need no separate permission. If it is not on it, you need written permission, applied for on the regulator's transfer form. The regulator answers within two months, and can extend that once. You cannot get transfer permission before the underlying use of the data has itself been declared or authorised. Narrow escape routes exist, such as the person's clear consent, or a transfer needed to perform a contract or to save someone's life.

High confidenceAllowlistOfficial 'this country is safe' decisionGovernment sign-off neededExplicit consentNeeded for a contractSomeone's life is at riskLegal claimsImportant public interestPut a transfer safeguard in place

The regulator, and whether it actually acts

Two regulators matter, and both are real. The privacy regulator is the National Commission for the Control of Personal Data Protection. It has a chairman who has been in post since November 2018 and six members appointed in January 2025, and it was still issuing decisions in late 2025 and signing agreements in 2026. The cyber regulator is the General Directorate for Information Systems Security, part of national defence administration. It issues binding licences to security auditors, runs the national incident team and investigated the 2025 data leaks. Neither publishes a stream of fines: the privacy law's penalties are criminal, so a court has to impose them.

Medium confidenceWaking up

How long you must keep it — and when to delete it

There is a floor and a ceiling, and they come from different laws. The ceiling is general: personal data may be kept only in a form that identifies people for as long as the purpose needs, and no longer. The floors are sector rules. Banks must keep the documents behind a customer's account for ten years. Payment institutions must keep a register of payment transactions for at least ten years. Telecoms operators, internet access providers, digital service providers and platform publishers must keep connection data, computer logs and security-event records for one year.

Medium confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

Count two clocks, and notice that one of them is missing. Public bodies, vital infrastructures, telecoms operators, internet access providers, digital service providers and platform publishers must report a cyber incident to the national cyber agency as soon as they know about it. The agency asks for it immediately, by a standard form sent to its incident team, with no fixed number of hours in the law. The missing clock is the privacy one: the 2009 privacy law contains no general duty to report a personal data breach to the regulator or to the people affected.

High confidenceReport cyber incidentsSecure the data

What catches people out

Five things that cost people their weekend. First, the United States is not an approved destination, so ordinary use of a big American cloud needs case-by-case permission, and Croatia is missing from the list while Britain is still on it. Second, the list of companies designated as vital infrastructure is kept secret by law, so you can be inside the strictest regime and only find out privately. Third, the penalties are criminal: up to one year in prison for a person, and fines doubled for a company. Fourth, a foreign company using equipment in Morocco must name a representative based there who inherits its obligations. Fifth, the top level of cloud licence requires Moroccan majority ownership and Moroccan staff, so a global cloud provider cannot qualify without a waiver signed off by the head of government.

High confidenceCriminal liabilityFixed maximum fineOrder to stopAppoint a local representativeKeep the data in the country

What's changing next

One hard date and several switches. The hard date is 21 August 2027: public bodies and vital infrastructures that were already using cloud services for sensitive systems or sensitive data must by then have moved to a provider licensed by the national cyber authority. Today no provider holds that licence, so everyone is relying on the temporary rule that lets you keep an unlicensed provider while none is available. The moment the first licence is granted, the duty to migrate starts to bite in practice. We found no bill to replace the 2009 privacy law on official sources, checked on 18 August 2026.

High confidenceIn forceKeep the data in the countryProve the data stays under local control

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Loi n° 05-20 relative à la cybersécurité

Act of parliament · Dahir n° 1-20-69 du 25 juillet 2020, Bulletin officiel n° 6906 du 6 août 2020; décret d'application n° 2-21-406 du 15 juillet 2021

In forceNo — it stays put

The hard wall. Sensitive data held by public bodies, and by any company the state has designated as vital infrastructure, must be hosted only in Morocco. The list of designated companies is secret by law. Hosting abroad is punished by a fine of up to 400,000 dirhams, about 44,000 United States dollars.

In force since 15 July 2021

Enforced by General Directorate for Information Systems Security

Transfer model: Not allowed

High confidence
Government

Décret n° 2-24-921 relatif au recours aux prestataires de services Cloud par les entités et les infrastructures d'importance vitale disposant de systèmes d'information ou de données sensibles

Directly binding regulation · Décret n° 2-24-921 du 22 octobre 2024, Bulletin officiel n° 7352 (arabe) et n° 7380 (français); arrêté n° 3-17-25 du 1er août 2025, Bulletin officiel n° 7432

In forceNo — it stays put

Sensitive cloud work for public bodies and vital infrastructures must go to a cloud provider licensed by the national cyber authority, with the strictest licence demanding Moroccan ownership, Moroccan staff and processing only in Morocco. Nobody holds that licence yet, so a temporary rule allows unlicensed providers, with a hard migration deadline of 21 August 2027.

In force since 21 August 2025But only enforceable from 21 August 2027

Enforced by General Directorate for Information Systems Security

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Government sign-off needed

High confidence
Telecoms

Loi n° 05-20 relative à la cybersécurité, dispositions propres aux opérateurs

Act of parliament · Loi n° 05-20, articles 26 to 34 and 50

In forceYes — store it anywhere

Telecoms operators, internet access providers, cyber security providers, digital service providers and internet platform publishers must keep connection records and logs for one year, follow the national cyber authority's directives, and warn customers about attacks. No rule found requiring that data to stay in Morocco, unless the operator is designated vital infrastructure.

In force since 15 July 2021

Enforced by General Directorate for Information Systems Security

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Loi n° 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel

Act of parliament · Dahir n° 1-09-15 du 18 février 2009, Bulletin officiel n° 5714 du 5 mars 2009

In forceYes, with paperwork

Morocco's general privacy law. Data can go abroad only to one of 32 countries the regulator has approved, or with its written permission. Processing must be declared, and sensitive processing authorised, before it starts. Penalties are criminal, including prison, and fines double for companies.

In force since 5 March 2009But only enforceable from 18 June 2009

Enforced by National Commission for the Control of the Protection of Personal Data

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Someone's life is at risk, Legal claims, Important public interest

High confidence

Délibération n° 236-2015 du 18 décembre 2015 portant modification de la délibération n° 465-2013 établissant la liste des Etats assurant une protection suffisante

Adequacy decision · CNDP, délibération n° 236-2015

In forceYes, with paperwork

The approved-destination list. Thirty-two countries are treated as offering sufficient protection, so data can go there on a notice rather than a permission. Croatia was never added, the United Kingdom is still on it, and the United States has never been on it.

In force since 18 December 2015

Enforced by National Commission for the Control of the Protection of Personal Data

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision

Medium confidence

Who you would hear from

  • Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)

    General personal data protection, declarations, prior authorisations and cross-border transfer permissions

    Constituted and working. The chairman has been in post since 17 November 2018 and six members were appointed on 24 January 2025. It issued five model deliberations on 28 November 2025 and was signing cooperation agreements through 2026. We found no published penalty decisions against named organisations on its own site: under the 2009 law fines and prison sentences are imposed by criminal courts, not by the Commission.

  • Direction Générale de la Sécurité des Systèmes d'Information (DGSSI)

    Cyber security law, sensitive data localisation, qualification of audit and cloud providers, national incident response (maCERT)

    Clearly operational. It publishes qualification decisions for security-audit providers running to 2029, updated its audit qualification standard in November 2025, published the cloud qualification standard in the official gazette in August 2025, and published the findings of its investigation into the June 2025 data leaks. Its list of qualified cloud providers was still empty on 18 August 2026.

  • بنك المغرب

    Banking, payment institutions, cloud outsourcing approvals

    Active supervisor with a published compendium of binding circulars and directives.

  • Autorité de Contrôle des Assurances et de la Prévoyance Sociale (ACAPS)

    Insurance and pension supervision

    Active: circular letters published as recently as 7 August 2026. No insurance-specific data localisation rule was located.

  • Autorité Marocaine du Marché des Capitaux (AMMC)

    Securities markets, market intermediaries, sanctions college

    Active: daily issuer publications through August 2026 and a standing sanctions college. No securities-specific data localisation rule was located.

  • Agence Nationale de Réglementation des Télécommunications (ANRT)

    Telecoms licensing and operator obligations

    We could not reach its website from outside Morocco on 18 August 2026, so its current licence conditions were not checked. The telecoms obligations recorded here come from the cyber security law, not from this agency.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the 2015 approved-country list is still the current list, unamended.

    The regulator's own transfer page still points to deliberation 236-2015, and no later amending deliberation was found. But the site publishes only a partial archive of deliberations, so a later amendment could exist without being visible.

  • Whether Morocco has ratified the modernised Convention 108+.

    The regulator's own deliberation confirms accession to the original Council of Europe Convention 108 on 28 May 2019. Its page on Convention 108+ did not state a ratification date when fetched.

  • Telecoms-sector rules on where operator data must sit, and licence conditions.

    The telecoms regulator's website was unreachable from outside Morocco on 18 August 2026, both through the fetch tool and directly.

  • That no insurance or securities data localisation rule exists.

    We reviewed the regulators' published regulation indexes but did not read every circular in full. Recorded as no rule found, checked 18 August 2026, rather than as an absence.

  • General tax and commercial record retention floors.

    The tax administration website returned an access-denied response. Only banking and payment retention periods are asserted here, from the central bank's own compendium.

  • Rules for online gambling, education technology and mapping or geospatial data.

    No official Moroccan source located for these sectors within this research run.

  • The exact entry-into-force date of the cloud decree: 21 August 2025 or 29 August 2025.

    The decree starts on the day the qualification standard is published in the official gazette. The gazette issue is dated 21 August 2025 but the cyber authority announced the publication on 29 August 2025. Plan to the earlier date, which makes the transition deadline 21 August 2027.

  • Whether a bill to replace or amend the 2009 privacy law is before parliament.

    The government's general secretariat and parliament websites were unreachable or blocked during this run, so we can only say no bill was found on the regulator's own site.

  • Whether any cloud provider was qualified between the check on 18 August 2026 and publication.

    The regulator's list is the authoritative source and it was empty when checked. It can be populated at any time without notice.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Morocco versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.