Skip to the content
Global Data RulesData governance rules, country by country

Morocco

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Morocco — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Waking up

Morocco lets personal data leave the country, but only to 32 approved countries. Otherwise you need permission from the privacy regulator, case by case. The United States is not on the approved list. Government bodies must keep their sensitive data in Morocco. So must companies the state has quietly labelled 'vital'. Sending that data abroad is a crime, not just a fine.

Data governance in Morocco

The eight things that decide how you handle data about people in Morocco. Same eight on every country page, so you can compare.

Who has to follow these rules

The privacy law reaches you in two situations. First, if you run any operation in Morocco, whatever its legal form. Second, if you have no office in Morocco but use equipment there to handle people's data. Having Moroccan customers is not enough on its own, if everything runs abroad. If the equipment test catches you, you must give the regulator the name of a representative based in Morocco. That person takes on your legal duties. There is no size or revenue cut-off.

What you have to do here:
Appoint a representative

Where the data is allowed to live

It depends who you are. For an ordinary business, data may leave only to a country on the regulator's approved list. Otherwise you need that regulator's written permission. The approved list has 32 countries. It covers the European Union states except Croatia, plus Britain, Switzerland, Norway, Iceland, Liechtenstein and Canada. The United States is not on it. For public bodies and companies named as vital infrastructure, sensitive data cannot leave at all. The cyber security law says it must be hosted only on Moroccan territory. Doing otherwise is a crime.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

You can only send data to approved countries, and the list is real. It has 32 countries on it. If your destination is on the list, you still file a transfer notice with the regulator, but you need no separate permission. If it is not on the list, you need written permission. You apply on the regulator's transfer form. The regulator answers within two months and can extend that once. You cannot get transfer permission until you have declared or been authorised for the underlying use of the data. There are narrow escape routes, such as the person's clear consent, or a transfer needed to perform a contract or to save someone's life.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · To save someone’s life · Legal claims · Important public interest

What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.

The regulator, and whether it actually acts

Two regulators matter, and both are real. The privacy regulator is the National Commission for the Control of Personal Data Protection. Its chairman has been in post since November 2018. Six members were appointed in January 2025. It was still issuing decisions in late 2025 and signing agreements in 2026. The cyber regulator is the General Directorate for Information Systems Security, part of the national defence administration. It issues binding licences to security auditors, runs the national incident team, and investigated the 2025 data leaks. Neither publishes a stream of fines. The privacy law's penalties are criminal, so a court has to impose them.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is a minimum and a maximum, and they come from different laws. The maximum is general. You may keep personal data in a form that identifies people only as long as your purpose needs it. The minimums are industry rules. Banks must keep the documents behind a customer's account for ten years. Payment institutions must keep a register of payment transactions for at least ten years. Telecoms operators, internet access providers, digital service providers and platform publishers must keep connection data, computer logs and security-event records for one year.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

Count two deadlines, and notice that one is missing. Public bodies and vital infrastructures must report a cyber incident to the national cyber agency as soon as they know about it. So must telecoms operators, internet access providers, digital service providers and platform publishers. The agency wants it immediately, on a standard form sent to its incident team. The law sets no fixed number of hours. The missing deadline is the privacy one. The 2009 privacy law has no general duty to report a personal data breach, either to the regulator or to the people affected.

What you have to do here:
Report cyber incidents · Secure the data

What catches people out

Five things that cost people their weekend. First, the United States is not an approved destination. So ordinary use of a big American cloud needs permission case by case. Croatia is missing from the list, while Britain is still on it. Second, the list of companies named as vital infrastructure is kept secret by law. You can be under the strictest rules and only find out privately. Third, the penalties are criminal. A person faces up to one year in prison, and fines double for a company. Fourth, a foreign company using equipment in Morocco must name a representative there, who inherits its duties. Fifth, the top level of cloud licence requires Moroccan majority ownership and Moroccan staff. A global cloud provider cannot qualify without a waiver signed off by the head of government.

What you have to do here:
Appoint a representative
What it costs if you get it wrong:
Criminal liability · Fixed maximum fine · Order to stop

What's changing next

One hard date, plus some powers already in someone's hand. The hard date is 21 August 2027. By then, public bodies and vital infrastructures must have moved to a provider licensed by the national cyber authority. That applies if they already use cloud services for sensitive systems or sensitive data. Today no provider holds that licence. So everyone relies on the temporary rule that lets you keep an unlicensed provider while none is available. Once the first licence is granted, the duty to move starts to matter. We found no bill to replace the 2009 privacy law on official sources, checked on 18 August 2026.

What you have to do here:
Prove the data stays under local control

What to do: Diarise 21 August 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data rules

Official name: Loi n° 05-20 relative à la cybersécurité · Dahir n° 1-20-69 du 25 juillet 2020, Bulletin officiel n° 6906 du 6 août 2020; décret d'application n° 2-21-406 du 15 juillet 2021 · Act of parliament

In forceNo — it stays put

Sensitive data held by public bodies must be hosted only in Morocco. The same goes for any company the state has named as vital infrastructure. The list of named companies is secret by law. Hosting abroad is punished by a fine of up to 400,000 dirhams, about 44,000 United States dollars.

In force since 15 July 2021

Enforced by General Directorate for Information Systems Security

How this country controls where data goes: Not allowed

Government

Cloud and outsourcing rules

Official name: Décret n° 2-24-921 relatif au recours aux prestataires de services Cloud par les entités et les infrastructures d'importance vitale disposant de systèmes d'information ou de données sensibles · Décret n° 2-24-921 du 22 octobre 2024, Bulletin officiel n° 7352 (arabe) et n° 7380 (français); arrêté n° 3-17-25 du 1er août 2025, Bulletin officiel n° 7432 · Directly binding regulation

In forceNo — it stays put

Sensitive cloud work for public bodies and vital infrastructures must go to a cloud provider licensed by the national cyber authority. The strictest licence demands Moroccan ownership, Moroccan staff, and the data being used only in Morocco. Nobody holds that licence yet. A temporary rule allows unlicensed providers, with a firm deadline to move by 21 August 2027.

In force since 21 August 2025In force now, but not enforced until 21 August 2027

That is a long gap: the duty is real law today, but no penalty can follow until 21 August 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by General Directorate for Information Systems Security

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Telecoms

Cyber security rules

Official name: Loi n° 05-20 relative à la cybersécurité, dispositions propres aux opérateurs · Loi n° 05-20, articles 26 to 34 and 50 · Act of parliament

In forceYes — store it anywhere

Telecoms operators, internet access providers, cyber security providers, digital service providers and internet platform publishers must keep connection records and logs for one year. They must follow the national cyber authority's directives and warn customers about attacks. We found no rule requiring that data to stay in Morocco, unless the operator is named as vital infrastructure.

In force since 15 July 2021

Enforced by General Directorate for Information Systems Security

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Loi n° 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel · Dahir n° 1-09-15 du 18 février 2009, Bulletin officiel n° 5714 du 5 mars 2009 · Act of parliament

In forceYes, with paperwork

Morocco's general privacy law. Data can go abroad only to one of 32 countries the regulator has approved, or with its written permission. You must declare how you use data before you start. Sensitive uses need permission first. Penalties are criminal, including prison, and fines double for companies.

In force since 5 March 2009Enforced from 18 June 2009

Enforced by National Commission for the Control of the Protection of Personal Data

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, To save someone’s life, Legal claims, Important public interest

Paperwork before personal data leaves

Official name: Délibération n° 236-2015 du 18 décembre 2015 portant modification de la délibération n° 465-2013 établissant la liste des Etats assurant une protection suffisante · CNDP, délibération n° 236-2015 · Official “this country is safe” decision

In forceYes, with paperwork

The approved-destination list. Thirty-two countries are treated as offering sufficient protection, so data can go there on a notice rather than a permission. Croatia was never added, the United Kingdom is still on it, and the United States has never been on it.

In force since 18 December 2015

Enforced by National Commission for the Control of the Protection of Personal Data

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)

    General personal data protection, declarations, prior authorisations and cross-border transfer permissions

    Set up and working. The chairman has been in post since 17 November 2018 and six members were appointed on 24 January 2025. It issued five model decisions on 28 November 2025 and was signing cooperation agreements through 2026. We found no published penalty decisions against named organisations on its own site. Under the 2009 law, fines and prison sentences come from the criminal courts, not from the Commission.

  • Direction Générale de la Sécurité des Systèmes d'Information (DGSSI)

    Cyber security law, sensitive keeping data in the country, qualification of audit and cloud providers, national incident response (maCERT)

    Clearly working. It publishes qualification decisions for security-audit providers running to 2029. It updated its audit qualification standard in November 2025. It published the cloud qualification standard in the official gazette in August 2025. It published the findings of its investigation into the June 2025 data leaks. Its list of qualified cloud providers was still empty on 18 August 2026.

  • بنك المغرب

    Banking, payment institutions, cloud outsourcing approvals

    Active supervisor with a published compendium of binding circulars and directives.

  • Autorité de Contrôle des Assurances et de la Prévoyance Sociale (ACAPS)

    Insurance and pension supervision

    Active. It published circular letters as recently as 7 August 2026. We found no insurance-specific rule that data must stay in the country.

  • Autorité Marocaine du Marché des Capitaux (AMMC)

    Securities markets, market intermediaries, sanctions college

    Active. It publishes issuer notices daily through August 2026 and has a standing sanctions panel. We found no securities-specific rule that data must stay in the country.

  • Agence Nationale de Réglementation des Télécommunications (ANRT)

    Telecoms licensing and operator obligations

    The telecoms duties recorded here come from the cyber security law, not from this agency.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the 2015 approved-country list is still the current list, unamended.

    The regulator's own transfer page still points to decision 236-2015, and we found no later decision changing it. But the site publishes only part of its archive. A later change could exist without being visible. Check the list before you rely on it.

  • Whether Morocco has ratified the modernised Convention 108+.

    The regulator's own decision confirms Morocco joined the original Council of Europe Convention 108 on 28 May 2019. We could not confirm a date for the updated Convention 108+.

  • Telecoms-sector rules on where operator data must sit, and licence conditions.

    We could not reach the telecoms regulator's website from outside Morocco on 18 August 2026. If you run a telecoms business here, ask the regulator directly for its licence conditions.

  • That no insurance or securities keeping data in the country rule exists.

    We reviewed the regulators' published indexes but did not read every circular in full. So this is 'we found no rule, checked 18 August 2026', not proof that none exists. Check with your regulator if you work in these industries.

  • General tax and commercial record retention floors.

    We could not confirm these against the tax administration's own site. We only state the banking and payment keep-it periods here, taken from the central bank's compendium. Check the general tax and commercial periods with your accountant.

  • Rules for online gambling, education technology and mapping or geospatial data.

    We found no official Moroccan source for these industries. If you work in one of them, check before you rely on this.

  • The exact entry-into-force date of the cloud decree: 21 August 2025 or 29 August 2025.

    The decree starts on the day the qualification standard is published in the official gazette. The gazette issue is dated 21 August 2025 but the cyber authority announced the publication on 29 August 2025. Plan to the earlier date, which makes the transition deadline 21 August 2027.

  • Whether a bill to replace or amend the 2009 privacy law is before parliament.

    We could not reach the government's general secretariat or parliament websites. So all we can say is that no bill appeared on the regulator's own site.

  • Whether any cloud provider was qualified between the check on 18 August 2026 and publication.

    The regulator's list is the official source, and it was empty when we checked. It can be filled at any time without notice. Check it before you plan a cloud move.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.