Morocco
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Morocco — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Morocco lets personal data leave the country, but only to 32 approved countries. Otherwise you need permission from the privacy regulator, case by case. The United States is not on the approved list. Government bodies must keep their sensitive data in Morocco. So must companies the state has quietly labelled 'vital'. Sending that data abroad is a crime, not just a fine.
Data governance in Morocco
The eight things that decide how you handle data about people in Morocco. Same eight on every country page, so you can compare.
Who has to follow these rules
The privacy law reaches you in two situations. First, if you run any operation in Morocco, whatever its legal form. Second, if you have no office in Morocco but use equipment there to handle people's data. Having Moroccan customers is not enough on its own, if everything runs abroad. If the equipment test catches you, you must give the regulator the name of a representative based in Morocco. That person takes on your legal duties. There is no size or revenue cut-off.
- What you have to do here:
- Appoint a representative
Law 09-08, article 2(2), covers two cases. It covers a company set up on Moroccan territory that uses people's data. It also covers a company not set up there that uses equipment located on Moroccan territory, whether automated or not. Data passing straight through does not count. Article 2(3) then makes that company tell the CNDP who its representative in Morocco is. That representative steps into the company's rights and duties under the law. The company stays liable as well. National defence and state security work is left out completely. Criminal-justice files are covered only by the law that creates them. Note what triggers the rule. It is equipment in Morocco, not the 'targeting' test used in Europe and India. So a fully offshore service with Moroccan users sits in a grey area, and the regulator has not settled it publicly.
Sources
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, article 2 (champ d'application) and article 2(3) (représentant installé au Maroc)
cndp.ma
“lorsque le responsable n'est pas établi sur le territoire marocain mais recourt, à des fins de traitement des données à caractère personnel, à des moyens automatisés ou non, situés sur le territoire marocain”
Link checked 18 August 2026
- Official sourceCNDPCNDP — Qui sommes-nous (mandate and composition)
cndp.ma
Link checked 18 August 2026
Where the data is allowed to live
It depends who you are. For an ordinary business, data may leave only to a country on the regulator's approved list. Otherwise you need that regulator's written permission. The approved list has 32 countries. It covers the European Union states except Croatia, plus Britain, Switzerland, Norway, Iceland, Liechtenstein and Canada. The United States is not on it. For public bodies and companies named as vital infrastructure, sensitive data cannot leave at all. The cyber security law says it must be hosted only on Moroccan territory. Doing otherwise is a crime.
- What you have to do here:
- Keep the data in the country
Industry by industry, checked on 18 August 2026. GOVERNMENT AND VITAL INFRASTRUCTURE. Closed. Law 05-20 article 11 says sensitive data must be hosted only on national territory. Article 14 extends the whole public-body chapter to vital infrastructures. On top of that, decree 2-24-921 requires a cloud provider qualified by the national authority. Level 1 covers sensitive systems and level 2 covers sensitive data. Level 2 demands that the data is used and stored only in Morocco. Even managing and supervising the service must happen only from Moroccan territory. BANKING. Paperwork works here. Bank Al-Maghrib's cloud directive 4/W/2022 requires the bank's prior agreement before outsourcing any significant function to the cloud. The bank must also control which countries may host its data. We found no rule in the central bank's own compendium forbidding hosting abroad. PAYMENTS. Same as banking, plus a ten-year register of payment transactions. TELECOMS AND ONLINE PLATFORMS. We found no rule that data must stay in Morocco. But network operators, internet access providers, digital service providers and internet platform publishers must keep connection data and logs for one year. They must also follow the national authority's directives. Any of them named as vital infrastructure falls under the must-stay-in-Morocco rule. HEALTH. Health data counts as sensitive data. So you need the privacy regulator's permission before you use it. You need a separate permission to send it to a country not on the approved list. Public hospitals are public bodies, so they must keep their sensitive data in Morocco. INSURANCE AND SECURITIES. We found no storage-location rule on the regulators' own sites, so the national rule applies. EDUCATION, GAMING AND MAPPING. We found no official rule. We record that as unconfirmed, not as proof that none exists.
Sources
- Official sourceCNDPDélibération CNDP n° 236-2015 du 18 décembre 2015 — list of states offering sufficient protection
cndp.ma
“la Commission considère que les pays suivants offrent un niveau de protection suffisant et conforme aux exigences de la législation marocaine”
Link checked 18 August 2026
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20 relative à la cybersécurité, articles 11, 14 and 49
dgssi.gov.ma
“Les données sensibles doivent être exclusivement hébergées sur le territoire national.”
Link checked 18 August 2026
- Official sourceDGSSI / Bulletin officiel n° 7380Décret n° 2-24-921 du 22 octobre 2024 relatif au recours aux prestataires de services Cloud, articles 2, 4 and 5
dgssi.gov.ma
“le traitement, l'exploitation et le stockage de données doivent être réalisés exclusivement sur le territoire national”
Link checked 18 August 2026
- Official sourceBank Al-MaghribBank Al-Maghrib, Recueil des textes législatifs et réglementaires — Directive n° 4/W/2022 du 19 mai 2022 (externalisation vers le cloud)
bkam.ma
“Tout projet d'externalisation de l'établissement de ses fonctions significatives vers le cloud doit recueillir l'accord préalable de Bank Al-Maghrib.”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
You can only send data to approved countries, and the list is real. It has 32 countries on it. If your destination is on the list, you still file a transfer notice with the regulator, but you need no separate permission. If it is not on the list, you need written permission. You apply on the regulator's transfer form. The regulator answers within two months and can extend that once. You cannot get transfer permission until you have declared or been authorised for the underlying use of the data. There are narrow escape routes, such as the person's clear consent, or a transfer needed to perform a contract or to save someone's life.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Government sign-off needed · Explicit consent · Needed for a contract · To save someone’s life · Legal claims · Important public interest
Law 09-08 article 43 allows a transfer only to a state that gives enough protection for privacy and basic rights. It gives the CNDP the job of listing those states. Article 44 sets out the exceptions. They are the person's explicit consent, protecting life, public interest, bringing or defending legal claims, performing a contract, medical treatment, an international agreement Morocco is party to, or an express CNDP permission where you show enough safeguards. So a bank or a software company running on United States cloud infrastructure needs the permission route. No United States arrangement appears on the 2015 list. Two oddities in that list. Croatia was never added after it joined the European Union. The United Kingdom is still on it years after leaving. Either could change with a single decision by the regulator.
Sources
- Official sourceCNDPCNDP — Notifier une demande de transfert à l'étranger (procedure, form F118, two-month decision period)
cndp.ma
“l'autorisation de transfert à l'étranger d'un fichier de données personnelles n'est accordée que lorsque le traitement sous-jacent a fait l'objet d'une demande”
Link checked 18 August 2026
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, articles 43 and 44 (transfert vers un pays étranger)
cndp.ma
Link checked 18 August 2026
- Official sourceCNDPDélibération CNDP n° 236-2015 — the 32 approved countries
cndp.ma
Link checked 18 August 2026
What to do: Budget months, not weeks: government sign-off has to be in hand before the data moves.
The regulator, and whether it actually acts
Two regulators matter, and both are real. The privacy regulator is the National Commission for the Control of Personal Data Protection. Its chairman has been in post since November 2018. Six members were appointed in January 2025. It was still issuing decisions in late 2025 and signing agreements in 2026. The cyber regulator is the General Directorate for Information Systems Security, part of the national defence administration. It issues binding licences to security auditors, runs the national incident team, and investigated the 2025 data leaks. Neither publishes a stream of fines. The privacy law's penalties are criminal, so a court has to impose them.
Here is the honest answer. The CNDP is set up and busy with registrations, permissions, model forms and awareness partnerships. But we found no published penalty decisions against named organisations on its own site. The law gives it ordering powers rather than a power to fine. It can order blocking, erasure, and a temporary or permanent ban on using the data. Fines and prison sentences under law 09-08 come from the criminal courts, on referral. The DGSSI is clearly working. Its published list of qualified security-audit providers carries qualification decisions running to 2029. It updated its audit qualification standard in November 2025. In June 2025 it published the results of its investigation into a leak, blaming a notaries' platform rather than the land registry agency. Its cloud qualification scheme, though, has qualified nobody yet. Overall the machinery exists and is moving, but public enforcement output is thin.
Sources
- Official sourceCNDPCNDP — composition: chairman since 17 November 2018, six members appointed 24 January 2025
cndp.ma
Link checked 18 August 2026
- Official sourceCNDPCNDP — deliberations D-939-2025 to D-943-2025, all dated 28 November 2025
cndp.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — qualified security-audit providers and qualified cloud providers, with qualification decision dates
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — Clarifications au sujet des récentes fuites de données, 6 June 2025
dgssi.gov.ma
“Il a été établi que les données concernées proviennent exclusivement de la plateforme tawtik.ma”
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and a maximum, and they come from different laws. The maximum is general. You may keep personal data in a form that identifies people only as long as your purpose needs it. The minimums are industry rules. Banks must keep the documents behind a customer's account for ten years. Payment institutions must keep a register of payment transactions for at least ten years. Telecoms operators, internet access providers, digital service providers and platform publishers must keep connection data, computer logs and security-event records for one year.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
Law 09-08 article 3 sets the maximum in general terms, with no fixed number of months. So you need a written keep-it schedule for each purpose. Law 05-20 article 26 sets the one-year minimum for technical data. It says expressly that the period can be changed by regulation, so it can move without a new law. Where a minimum and the maximum clash, the minimum normally wins, because keeping the data becomes a legal duty. The safe approach is to separate the legally required records and delete everything else on schedule. We could not open the tax administration's own site to confirm the general commercial and tax keep-it periods, so we do not state them here.
Sources
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, article 3 (données conservées pendant une durée n'excédant pas celle nécessaire)
cndp.ma
Link checked 18 August 2026
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, article 26 (conservation des données techniques)
dgssi.gov.ma
“La durée de conservation des données techniques nécessaires à l'identification et à l'analyse de l'incident est fixée à une année.”
Link checked 18 August 2026
- Official sourceBank Al-MaghribBank Al-Maghrib compendium — ten-year retention of account documents, and payment institutions' ten-year transaction register
bkam.ma
“L'établissement de paiement doit tenir un registre interne des opérations de paiement, à conserver pour une période d'au moins 10 ans”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
Count two deadlines, and notice that one is missing. Public bodies and vital infrastructures must report a cyber incident to the national cyber agency as soon as they know about it. So must telecoms operators, internet access providers, digital service providers and platform publishers. The agency wants it immediately, on a standard form sent to its incident team. The law sets no fixed number of hours. The missing deadline is the privacy one. The 2009 privacy law has no general duty to report a personal data breach, either to the regulator or to the people affected.
- What you have to do here:
- Report cyber incidents · Secure the data
Law 05-20 article 8 makes each public body report an incident affecting the security or running of its information systems as soon as it knows. It must also supply more information on request without delay. Article 14 extends this to vital infrastructures. Article 30 extends it to operators, access providers, cyber security providers, digital service providers and internet platform publishers. Those must also warn their own customers about weaknesses affecting them. Failing to report is punished by a fine of 100,000 to 200,000 dirhams, roughly 11,000 to 22,000 United States dollars. The privacy law has no breach-reporting article. So the duty to tell customers usually comes from your contracts, from foreign law such as Europe's, or from your industry regulator. It does not come from Moroccan privacy law.
Sources
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, articles 8, 14, 27, 30 and 50 (déclaration des incidents et amendes)
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — Déclaration d'incidents (maCERT reporting channel)
dgssi.gov.ma
“Le maCERT incite toutes les Administrations, Organismes publiques et infrastructures d'importances vitales à déclarer dans l'immédiat tout incident de sécurité cyber.”
Link checked 18 August 2026
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08 — no general personal data breach notification duty found in the text, checked 18 August 2026
cndp.ma
Link checked 18 August 2026
What catches people out
Five things that cost people their weekend. First, the United States is not an approved destination. So ordinary use of a big American cloud needs permission case by case. Croatia is missing from the list, while Britain is still on it. Second, the list of companies named as vital infrastructure is kept secret by law. You can be under the strictest rules and only find out privately. Third, the penalties are criminal. A person faces up to one year in prison, and fines double for a company. Fourth, a foreign company using equipment in Morocco must name a representative there, who inherits its duties. Fifth, the top level of cloud licence requires Moroccan majority ownership and Moroccan staff. A global cloud provider cannot qualify without a waiver signed off by the head of government.
- What you have to do here:
- Appoint a representative
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine · Order to stop
On the criminal point. Law 09-08 punishes running a file without the required declaration or permission. The fine is 10,000 to 100,000 dirhams, roughly 1,100 to 11,000 United States dollars. Unlawful international transfer carries three months to one year in prison and 20,000 to 200,000 dirhams. Using sensitive data without consent carries three months to one year and 50,000 to 300,000 dirhams, about 33,000 US dollars. Article 64 doubles the fines for companies and allows confiscation or closure of the premises. Article 65 doubles everything again on a repeat offence. On the vital-infrastructure point. Law 05-20 article 16 says the list of these infrastructures must be kept secret and refreshed at least every two years. Article 18 says the list of their sensitive systems is secret too. On the cloud point. Decree 2-24-921 article 5 requires, for level 2, Moroccan majority ownership and Moroccan-national operating staff. It also bans any foreign group company from accessing the data. A waiver is possible only with the prior agreement of the head of government.
Sources
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, articles 52 to 65 (sanctions pénales, doublement pour les personnes morales)
cndp.ma
Link checked 18 August 2026
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, articles 16 and 18 (secrecy of the vital infrastructure and sensitive system lists)
dgssi.gov.ma
“La liste de ces infrastructures doit être tenue secrète et doit être actualisée à intervalles réguliers et au moins tous les deux ans.”
Link checked 18 August 2026
- Official sourceDGSSI / Bulletin officiel n° 7380Décret n° 2-24-921, article 5 (level 2 ownership, staffing and waiver)
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — declaration of sensitive information systems of vital infrastructures
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceCNDPDélibération CNDP n° 236-2015 — approved countries, no United States, no Croatia
cndp.ma
Link checked 18 August 2026
What's changing next
One hard date, plus some powers already in someone's hand. The hard date is 21 August 2027. By then, public bodies and vital infrastructures must have moved to a provider licensed by the national cyber authority. That applies if they already use cloud services for sensitive systems or sensitive data. Today no provider holds that licence. So everyone relies on the temporary rule that lets you keep an unlicensed provider while none is available. Once the first licence is granted, the duty to move starts to matter. We found no bill to replace the 2009 privacy law on official sources, checked on 18 August 2026.
- What you have to do here:
- Prove the data stays under local control
Powers already in someone's hand. Each can move with no consultation. One: the regulator can rewrite the approved-country list with a single decision. It could add the United States or remove the United Kingdom. Two: any company can be named as vital infrastructure by the ministry that covers its industry, in secret. That pulls it under the must-stay-in-Morocco rules. Three: the head of government can waive the Moroccan-ownership requirement for a cloud provider, case by case. That is the only realistic path for a global provider. Four: the one-year keep-it period for technical data can be changed by regulation. Five: the national cyber authority can impose industry-specific security rules on vital infrastructures, at their own cost. The decree came into force when the qualification standard was published in the official gazette issue dated 21 August 2025. The twenty-four month transition runs from that date.
Sources
- Official sourceDGSSI / Bulletin officiel n° 7380Décret n° 2-24-921, articles 17, 18 and 19 (transition, 24-month deadline, entry into force)
dgssi.gov.ma
“doivent se conformer aux dispositions du présent décret dans un délai maximum de vingt-quatre (24) mois à compter de la date de son entrée en vigueur”
Link checked 18 August 2026
- Official sourceDGSSI / Bulletin officielArrêté du Chef du gouvernement n° 3-17-25 du 1er août 2025 fixant le référentiel des exigences de qualification des prestataires de services Cloud, Bulletin officiel n° 7432 du 21 août 2025
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — list of qualified cloud providers, empty as at 18 August 2026
dgssi.gov.ma
“Aucun service disponible pour le moment.”
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — full list of legislative and regulatory texts in force
dgssi.gov.ma
Link checked 18 August 2026
What to do: Diarise 21 August 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data rules
Official name: Loi n° 05-20 relative à la cybersécurité · Dahir n° 1-20-69 du 25 juillet 2020, Bulletin officiel n° 6906 du 6 août 2020; décret d'application n° 2-21-406 du 15 juillet 2021 · Act of parliament
Sensitive data held by public bodies must be hosted only in Morocco. The same goes for any company the state has named as vital infrastructure. The list of named companies is secret by law. Hosting abroad is punished by a fine of up to 400,000 dirhams, about 44,000 United States dollars.
Enforced by General Directorate for Information Systems Security
How this country controls where data goes: Not allowed
What you have to do
- Keep the data in the countrySensitive data must be hosted exclusively on national territory. Applies to state administrations, local authorities, public establishments and enterprises, other public-law bodies, and to designated vital infrastructures.
- Secure the data
- Appoint a data protection officerAn information systems security officer who is the national authority's contact point and must be independent.
- Independent auditSensitive systems must be audited by providers qualified by the national authority, at the operator's cost.
- Hold a security certificateEvery sensitive information system needs a formal security homologation before it goes live.
- Written vendor contractIf you outsource a sensitive information system, the contract must be governed by Moroccan law. It must promise protection, the right to audit, and the ability to reverse the arrangement.
- Report cyber incidentsDeclare incidents to the national authority as soon as you know.
What it costs if you get it wrong
- Fixed maximum fine: MAD 400,000 — about $44 thousandHosting sensitive data outside national territory
- Fixed maximum fine: MAD 200,000 — about $22 thousandFailure to declare a cyber incident
- Criminal liability: Doubled penalties on repeat offence within four yearsRepeat offence
Sources
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, articles 10 to 14, 19, 20, 25 and 49
dgssi.gov.ma
“Les données sensibles doivent être exclusivement hébergées sur le territoire national.”
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — sensitive information systems of vital infrastructures: classification, declaration and secrecy
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — legislative and regulatory texts, including décret n° 2-21-406 of 15 July 2021
dgssi.gov.ma
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Décret n° 2-24-921 relatif au recours aux prestataires de services Cloud par les entités et les infrastructures d'importance vitale disposant de systèmes d'information ou de données sensibles · Décret n° 2-24-921 du 22 octobre 2024, Bulletin officiel n° 7352 (arabe) et n° 7380 (français); arrêté n° 3-17-25 du 1er août 2025, Bulletin officiel n° 7432 · Directly binding regulation
Sensitive cloud work for public bodies and vital infrastructures must go to a cloud provider licensed by the national cyber authority. The strictest licence demands Moroccan ownership, Moroccan staff, and the data being used only in Morocco. Nobody holds that licence yet. A temporary rule allows unlicensed providers, with a firm deadline to move by 21 August 2027.
That is a long gap: the duty is real law today, but no penalty can follow until 21 August 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by General Directorate for Information Systems Security
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the country — from 21 August 2025Level 1 providers must put all hosting infrastructure in Morocco. Level 2 providers must use, run and store the data only in Morocco. They must also manage and supervise the service only from Morocco.
- Prove the data stays under local controlLevel 2 also requires Moroccan majority ownership, Moroccan-national operating staff, and a ban on any other party accessing the customer's data without the customer's prior agreement. A waiver needs the head of government's prior agreement.
- Hold a security certificateProviders are qualified for a maximum of five years against a published requirements standard, and are audited by the national authority.
- Make switching cloud provider possibleOn exit the provider must hand back the systems and data, then certify their deletion.
- Assess high-risk projects — from 21 August 2025While no qualified provider exists, you must write up a risk and impact analysis before using an unqualified one. Once a qualified provider appears, you must move to it.
- Independent audit
What it costs if you get it wrong
- Fixed maximum fine: MAD 400,000 — about $44 thousandRelated breaches of the cyber security law, including hosting sensitive data abroad and using unqualified providers for regulated services
Sources
- Official sourceDGSSI / Bulletin officiel n° 7380Décret n° 2-24-921, full text as published in the Bulletin officiel
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSI / Bulletin officielArrêté n° 3-17-25 du 1er août 2025 (Bulletin officiel n° 7432 du 21 août 2025), which triggered entry into force
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — qualified cloud provider list, empty on 18 August 2026
dgssi.gov.ma
“Aucun service disponible pour le moment.”
Link checked 18 August 2026
Cyber security rules
Official name: Loi n° 05-20 relative à la cybersécurité, dispositions propres aux opérateurs · Loi n° 05-20, articles 26 to 34 and 50 · Act of parliament
Telecoms operators, internet access providers, cyber security providers, digital service providers and internet platform publishers must keep connection records and logs for one year. They must follow the national cyber authority's directives and warn customers about attacks. We found no rule requiring that data to stay in Morocco, unless the operator is named as vital infrastructure.
Enforced by General Directorate for Information Systems Security
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep logs — 1 yearConnection data, computer logs and security-event traces. The period can be changed by regulation.
- Report cyber incidentsTell the national authority without delay about events that could affect customers' systems.
- Tell people what you doWarn customers about vulnerabilities or attacks affecting them.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: MAD 200,000 — about $22 thousandFailing the retention and directive obligations, or obstructing the national authority
Sources
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, articles 26 to 30 and 50
dgssi.gov.ma
“La durée de conservation des données techniques nécessaires à l'identification et à l'analyse de l'incident est fixée à une année.”
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — texts including loi n° 24-96 on posts and telecommunications
dgssi.gov.ma
Link checked 18 August 2026
Cloud and outsourcing rules (Banking)
Official name: Directive n° 4/W/2022 fixant les règles minimales en matière d'externalisation vers le cloud par les établissements de crédit · Bank Al-Maghrib, directive n° 4/W/2022 du 19 mai 2022 · Regulator directive
Banks and payment institutions may use foreign cloud. But outsourcing any significant function to the cloud needs Bank Al-Maghrib's prior agreement. The bank must itself decide and enforce which countries may host its data. We found no Moroccan banking rule requiring the data to stay in the country.
Enforced by Bank Al-Maghrib
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision
What you have to do
- Written vendor contractThe contract must fix data location by country or region, subcontracting limits, audit rights and an exit plan.
- Independent auditThe bank must be able to control and inspect outsourced functions, and Bank Al-Maghrib may access information about them at any time.
- Put a transfer safeguard in placeThe bank must check that its cloud provider follows the privacy law on transfers abroad. It must also set the list of allowed hosting countries itself.
- Make switching cloud provider possibleA documented, tested exit strategy is required.
- Keep data for a minimum period — 10 yearsTen years for the documents behind customer accounts, and for payment institutions' transaction registers.
What it costs if you get it wrong
- Loss of your licenceSupervisory action by Bank Al-Maghrib for breach of prudential directives
Sources
- Official sourceBank Al-MaghribBank Al-Maghrib, Recueil des textes législatifs et réglementaires (updated to end 2023) — directive n° 4/W/2022, articles 8 to 14
bkam.ma
“Tout projet d'externalisation de l'établissement de ses fonctions significatives vers le cloud doit recueillir l'accord préalable de Bank Al-Maghrib.”
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Loi n° 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel · Dahir n° 1-09-15 du 18 février 2009, Bulletin officiel n° 5714 du 5 mars 2009 · Act of parliament
Morocco's general privacy law. Data can go abroad only to one of 32 countries the regulator has approved, or with its written permission. You must declare how you use data before you start. Sensitive uses need permission first. Penalties are criminal, including prison, and fines double for companies.
Enforced by National Commission for the Control of the Protection of Personal Data
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, To save someone’s life, Legal claims, Important public interest
What you have to do
- Register or notifyYou must declare every use of personal data to the regulator. Sensitive data, genetic data, criminal records, national identity numbers and linking files together all need permission first.
- Appoint a representativeYou must do this if you are not set up in Morocco but use equipment located there. The representative steps into your rights and duties.
- Tell people what you do
- Get consent
- Let people see their data
- Let people correct their data
- Let people object
- Secure the data
- Put a transfer safeguard in placeFile a transfer notice for approved destinations. For all others you need written permission, decided within two months and extendable once.
- Delete data after a periodNo fixed period. Data may identify people only as long as the purpose requires.
What it costs if you get it wrong
- Criminal liability: 1 year imprisonment and MAD 200,000 — about $22 thousandTransferring personal data abroad in breach of the transfer rules
- Criminal liability: 1 year imprisonment and MAD 300,000 — about $33 thousandProcessing sensitive data without the required consent
- Fixed maximum fine: MAD 100,000 — about $11 thousandRunning a file without the required declaration or authorisation
- Fixed maximum fine: MAD 600,000 (fines doubled for companies) — about $66 thousandAny offence committed by a legal person; confiscation or closure of premises also available
- Order to stop: Temporary or permanent ban on processingRegulator order under its investigation powers
Sources
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, full text
cndp.ma
Link checked 18 August 2026
- Official sourceCNDPCNDP — transfer procedure and two-month decision period
cndp.ma
Link checked 18 August 2026
Paperwork before personal data leaves
Official name: Délibération n° 236-2015 du 18 décembre 2015 portant modification de la délibération n° 465-2013 établissant la liste des Etats assurant une protection suffisante · CNDP, délibération n° 236-2015 · Official “this country is safe” decision
The approved-destination list. Thirty-two countries are treated as offering sufficient protection, so data can go there on a notice rather than a permission. Croatia was never added, the United Kingdom is still on it, and the United States has never been on it.
Enforced by National Commission for the Control of the Protection of Personal Data
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision
What you have to do
- Put a transfer safeguard in place32 approved countries: the European Union states except Croatia, plus Iceland, Liechtenstein, Norway, Switzerland, the United Kingdom and Canada. The United States is not listed.
Sources
- Official sourceCNDPDélibération CNDP n° 236-2015 du 18 décembre 2015
cndp.ma
Link checked 18 August 2026
- Official sourceCNDPCNDP transfer page, which still points to deliberation 236-2015 as the operative list
cndp.ma
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the 2015 approved-country list is still the current list, unamended.
The regulator's own transfer page still points to decision 236-2015, and we found no later decision changing it. But the site publishes only part of its archive. A later change could exist without being visible. Check the list before you rely on it.
Whether Morocco has ratified the modernised Convention 108+.
The regulator's own decision confirms Morocco joined the original Council of Europe Convention 108 on 28 May 2019. We could not confirm a date for the updated Convention 108+.
Telecoms-sector rules on where operator data must sit, and licence conditions.
We could not reach the telecoms regulator's website from outside Morocco on 18 August 2026. If you run a telecoms business here, ask the regulator directly for its licence conditions.
That no insurance or securities keeping data in the country rule exists.
We reviewed the regulators' published indexes but did not read every circular in full. So this is 'we found no rule, checked 18 August 2026', not proof that none exists. Check with your regulator if you work in these industries.
General tax and commercial record retention floors.
We could not confirm these against the tax administration's own site. We only state the banking and payment keep-it periods here, taken from the central bank's compendium. Check the general tax and commercial periods with your accountant.
Rules for online gambling, education technology and mapping or geospatial data.
We found no official Moroccan source for these industries. If you work in one of them, check before you rely on this.
The exact entry-into-force date of the cloud decree: 21 August 2025 or 29 August 2025.
The decree starts on the day the qualification standard is published in the official gazette. The gazette issue is dated 21 August 2025 but the cyber authority announced the publication on 29 August 2025. Plan to the earlier date, which makes the transition deadline 21 August 2027.
Whether a bill to replace or amend the 2009 privacy law is before parliament.
We could not reach the government's general secretariat or parliament websites. So all we can say is that no bill appeared on the regulator's own site.
Whether any cloud provider was qualified between the check on 18 August 2026 and publication.
The regulator's list is the official source, and it was empty when we checked. It can be filled at any time without notice. Check it before you plan a cloud move.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.