Morocco
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Morocco lets personal data leave the country, but only to 32 approved countries, or with case-by-case permission from the privacy regulator. The United States is not on the approved list. Government bodies, and companies the state has quietly labelled "vital", must keep their sensitive data on Moroccan soil. Sending it abroad is a crime, not just a fine.
Data governance in Morocco
The eight things that decide how you handle data about people in Morocco. Same eight on every country page, so you can compare.
Who has to follow these rules
The privacy law reaches you in two situations. First, if you run any operation in Morocco, whatever its legal form. Second, if you have no office in Morocco but use equipment there to handle people's data. Just having Moroccan customers, with everything running abroad, is not by itself enough. If the equipment test catches you, you must give the regulator the name of a representative based in Morocco, and that person takes on your legal duties. There is no size or revenue threshold to fall below.
Law 09-08, article 2(2) covers processing by a controller established on Moroccan territory, and processing by a controller not established there who uses automated or non-automated means located on Moroccan territory, excluding pure transit. Article 2(3) then requires that controller to notify the CNDP of the identity of a representative installed in Morocco who, without prejudice to the controller's own liability, substitutes for the controller in all rights and obligations under the law. National defence and state security processing is carved out entirely; criminal-justice files are covered only under the instrument that creates them. Note the trigger is means in Morocco, not the "targeting" test used in Europe and India, so a purely offshore service with Moroccan users sits in a grey zone that the regulator has not publicly resolved.
Sources
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, article 2 (champ d'application) and article 2(3) (représentant installé au Maroc)
cndp.ma
“lorsque le responsable n'est pas établi sur le territoire marocain mais recourt, à des fins de traitement des données à caractère personnel, à des moyens automatisés ou non, situés sur le territoire marocain”
Link checked 18 August 2026
- Official sourceCNDPCNDP — Qui sommes-nous (mandate and composition)
cndp.ma
Link checked 18 August 2026
Where the data is allowed to live
It depends who you are. For ordinary business, data may leave only to a country on the regulator's approved list, or with that regulator's written permission. The approved list has 32 countries: the European Union states except Croatia, plus Britain, Switzerland, Norway, Iceland, Liechtenstein and Canada. The United States is not on it. For public bodies and for companies designated as vital infrastructure, sensitive data cannot leave at all: the cyber security law says it must be hosted only on Moroccan territory, and doing otherwise is a criminal offence.
Sector by sector, as checked on 18 August 2026. GOVERNMENT AND VITAL INFRASTRUCTURE: closed. Law 05-20 article 11 says sensitive data must be hosted exclusively on national territory, and article 14 extends the whole public-entity chapter to vital infrastructures. On top of that, decree 2-24-921 requires a cloud provider qualified by the national authority for sensitive systems (level 1) and sensitive data (level 2); level 2 demands that processing and storage, and even management and supervision of the service, happen exclusively from and on Moroccan territory. BANKING: conditional, not closed. Bank Al-Maghrib's cloud directive 4/W/2022 requires the bank's prior agreement before outsourcing any significant function to the cloud, and requires the institution to control which countries are eligible to host its data, but we found no rule in the central bank's own compendium forbidding hosting abroad. PAYMENTS: same as banking, plus a ten-year register of payment transactions. TELECOMS AND ONLINE PLATFORMS: no localisation rule found, but network operators, internet access providers, digital service providers and internet platform publishers must retain connection data and logs for one year and follow the national authority's directives; any of them designated vital infrastructure falls under the localisation rule. HEALTH: health data is sensitive data, so processing needs the privacy regulator's prior authorisation and a transfer outside the approved list needs a separate permission; public hospitals are public entities and therefore inside the localisation rule. INSURANCE AND SECURITIES: no localisation rule located on the regulators' own sites, so treat as the national rule. EDUCATION, GAMING AND MAPPING: no official rule located, recorded as unconfirmed rather than as an absence.
Sources
- Official sourceCNDPDélibération CNDP n° 236-2015 du 18 décembre 2015 — list of states offering sufficient protection
cndp.ma
“la Commission considère que les pays suivants offrent un niveau de protection suffisant et conforme aux exigences de la législation marocaine”
Link checked 18 August 2026
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20 relative à la cybersécurité, articles 11, 14 and 49
dgssi.gov.ma
“Les données sensibles doivent être exclusivement hébergées sur le territoire national.”
Link checked 18 August 2026
- Official sourceDGSSI / Bulletin officiel n° 7380Décret n° 2-24-921 du 22 octobre 2024 relatif au recours aux prestataires de services Cloud, articles 2, 4 and 5
dgssi.gov.ma
“le traitement, l'exploitation et le stockage de données doivent être réalisés exclusivement sur le territoire national”
Link checked 18 August 2026
- Official sourceBank Al-MaghribBank Al-Maghrib, Recueil des textes législatifs et réglementaires — Directive n° 4/W/2022 du 19 mai 2022 (externalisation vers le cloud)
bkam.ma
“Tout projet d'externalisation de l'établissement de ses fonctions significatives vers le cloud doit recueillir l'accord préalable de Bank Al-Maghrib.”
Link checked 18 August 2026
Sending data out of the country
The model is an approved list, and the list is real and populated with 32 countries. If your destination is on it, you still file a transfer notice with the regulator, but you need no separate permission. If it is not on it, you need written permission, applied for on the regulator's transfer form. The regulator answers within two months, and can extend that once. You cannot get transfer permission before the underlying use of the data has itself been declared or authorised. Narrow escape routes exist, such as the person's clear consent, or a transfer needed to perform a contract or to save someone's life.
Law 09-08 article 43 allows transfer only to a state ensuring a sufficient level of protection of privacy and fundamental rights, and gives the CNDP the job of listing those states. Article 44 sets out the exceptions: explicit consent of the person, protection of life, public interest, exercise or defence of legal claims, performance of a contract, medical treatment, an international agreement to which Morocco is party, or an express CNDP authorisation granted where sufficient guarantees are shown. In practice a bank or a software company running on United States cloud infrastructure needs the authorisation route, because no United States mechanism appears on the 2015 list. Two quirks in that list: Croatia was never added after it joined the European Union, and the United Kingdom is still on it years after leaving. Both are one deliberation away from changing.
Sources
- Official sourceCNDPCNDP — Notifier une demande de transfert à l'étranger (procedure, form F118, two-month decision period)
cndp.ma
“l'autorisation de transfert à l'étranger d'un fichier de données personnelles n'est accordée que lorsque le traitement sous-jacent a fait l'objet d'une demande”
Link checked 18 August 2026
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, articles 43 and 44 (transfert vers un pays étranger)
cndp.ma
Link checked 18 August 2026
- Official sourceCNDPDélibération CNDP n° 236-2015 — the 32 approved countries
cndp.ma
Link checked 18 August 2026
The regulator, and whether it actually acts
Two regulators matter, and both are real. The privacy regulator is the National Commission for the Control of Personal Data Protection. It has a chairman who has been in post since November 2018 and six members appointed in January 2025, and it was still issuing decisions in late 2025 and signing agreements in 2026. The cyber regulator is the General Directorate for Information Systems Security, part of national defence administration. It issues binding licences to security auditors, runs the national incident team and investigated the 2025 data leaks. Neither publishes a stream of fines: the privacy law's penalties are criminal, so a court has to impose them.
This is the honest picture. The CNDP is constituted and busy on registration, authorisations, model forms and awareness partnerships, but we found no published penalty decisions against named organisations on its own site, and the law gives it ordering powers (blocking, erasure, a temporary or permanent ban on processing) rather than a power to fine. Fines and prison sentences under law 09-08 come from the criminal courts on referral. The DGSSI is visibly operational: its published list of qualified security-audit providers carries qualification decisions running to 2029, and in June 2025 it published the results of its investigation into a leak, attributing it to a notaries' platform rather than the land registry agency. Its cloud qualification regime, however, has qualified nobody yet. Overall this is a waking regime rather than an active one: the machinery exists and is moving, but public enforcement output is thin.
Sources
- Official sourceCNDPCNDP — composition: chairman since 17 November 2018, six members appointed 24 January 2025
cndp.ma
Link checked 18 August 2026
- Official sourceCNDPCNDP — deliberations D-939-2025 to D-943-2025, all dated 28 November 2025
cndp.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — qualified security-audit providers and qualified cloud providers, with qualification decision dates
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — Clarifications au sujet des récentes fuites de données, 6 June 2025
dgssi.gov.ma
“Il a été établi que les données concernées proviennent exclusivement de la plateforme tawtik.ma”
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling, and they come from different laws. The ceiling is general: personal data may be kept only in a form that identifies people for as long as the purpose needs, and no longer. The floors are sector rules. Banks must keep the documents behind a customer's account for ten years. Payment institutions must keep a register of payment transactions for at least ten years. Telecoms operators, internet access providers, digital service providers and platform publishers must keep connection data, computer logs and security-event records for one year.
Law 09-08 article 3 sets the ceiling in general terms, with no fixed number of months, so the practical answer is a documented retention schedule per purpose. Law 05-20 article 26 sets the one-year floor for technical data and expressly says it can be changed by regulation, which makes it a dormant switch. Where a floor and the ceiling collide, the floor normally wins because keeping the data becomes a legal obligation, but the safe practice is to segregate the legally required records and delete everything else on schedule. We could not open the tax administration's own site to confirm the general commercial and tax retention periods, so those are not asserted here.
Sources
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, article 3 (données conservées pendant une durée n'excédant pas celle nécessaire)
cndp.ma
Link checked 18 August 2026
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, article 26 (conservation des données techniques)
dgssi.gov.ma
“La durée de conservation des données techniques nécessaires à l'identification et à l'analyse de l'incident est fixée à une année.”
Link checked 18 August 2026
- Official sourceBank Al-MaghribBank Al-Maghrib compendium — ten-year retention of account documents, and payment institutions' ten-year transaction register
bkam.ma
“L'établissement de paiement doit tenir un registre interne des opérations de paiement, à conserver pour une période d'au moins 10 ans”
Link checked 18 August 2026
If something goes wrong
Count two clocks, and notice that one of them is missing. Public bodies, vital infrastructures, telecoms operators, internet access providers, digital service providers and platform publishers must report a cyber incident to the national cyber agency as soon as they know about it. The agency asks for it immediately, by a standard form sent to its incident team, with no fixed number of hours in the law. The missing clock is the privacy one: the 2009 privacy law contains no general duty to report a personal data breach to the regulator or to the people affected.
Law 05-20 article 8 requires each public entity to declare an incident affecting the security or operation of its information systems as soon as it becomes aware of it, and to supply further information on request without delay. Article 14 extends this to vital infrastructures and article 30 to operators, access providers, cyber security providers, digital service providers and internet platform publishers, who must also warn their own customers about vulnerabilities affecting them. Failing to declare is punishable by a fine of 100,000 to 200,000 dirhams, roughly 11,000 to 22,000 United States dollars. Because the privacy law has no breach-notification article, in practice the duty to tell customers usually comes from contracts, from foreign law such as Europe's, or from the sector regulator, not from Moroccan privacy law.
Sources
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, articles 8, 14, 27, 30 and 50 (déclaration des incidents et amendes)
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — Déclaration d'incidents (maCERT reporting channel)
dgssi.gov.ma
“Le maCERT incite toutes les Administrations, Organismes publiques et infrastructures d'importances vitales à déclarer dans l'immédiat tout incident de sécurité cyber.”
Link checked 18 August 2026
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08 — no general personal data breach notification duty found in the text, checked 18 August 2026
cndp.ma
Link checked 18 August 2026
What catches people out
Five things that cost people their weekend. First, the United States is not an approved destination, so ordinary use of a big American cloud needs case-by-case permission, and Croatia is missing from the list while Britain is still on it. Second, the list of companies designated as vital infrastructure is kept secret by law, so you can be inside the strictest regime and only find out privately. Third, the penalties are criminal: up to one year in prison for a person, and fines doubled for a company. Fourth, a foreign company using equipment in Morocco must name a representative based there who inherits its obligations. Fifth, the top level of cloud licence requires Moroccan majority ownership and Moroccan staff, so a global cloud provider cannot qualify without a waiver signed off by the head of government.
On the criminal point: law 09-08 punishes running a file without the required declaration or authorisation with a fine of 10,000 to 100,000 dirhams, roughly 1,100 to 11,000 United States dollars; unlawful international transfer with three months to one year in prison and 20,000 to 200,000 dirhams; and processing sensitive data without consent with three months to one year and 50,000 to 300,000 dirhams, about 33,000 dollars. Article 64 doubles the fines for legal persons and allows confiscation or closure of the premises, and article 65 doubles everything again on a repeat offence. On the vital-infrastructure point: law 05-20 article 16 says the list of these infrastructures must be kept secret and refreshed at least every two years, and article 18 says the list of their sensitive systems is secret too. On the cloud point: decree 2-24-921 article 5 requires, for level 2, Moroccan majority ownership, Moroccan-national operating staff, and a ban on any foreign group company accessing the data, with an exceptional waiver possible only with the prior agreement of the head of government.
Sources
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, articles 52 to 65 (sanctions pénales, doublement pour les personnes morales)
cndp.ma
Link checked 18 August 2026
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, articles 16 and 18 (secrecy of the vital infrastructure and sensitive system lists)
dgssi.gov.ma
“La liste de ces infrastructures doit être tenue secrète et doit être actualisée à intervalles réguliers et au moins tous les deux ans.”
Link checked 18 August 2026
- Official sourceDGSSI / Bulletin officiel n° 7380Décret n° 2-24-921, article 5 (level 2 ownership, staffing and waiver)
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — declaration of sensitive information systems of vital infrastructures
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceCNDPDélibération CNDP n° 236-2015 — approved countries, no United States, no Croatia
cndp.ma
Link checked 18 August 2026
What's changing next
One hard date and several switches. The hard date is 21 August 2027: public bodies and vital infrastructures that were already using cloud services for sensitive systems or sensitive data must by then have moved to a provider licensed by the national cyber authority. Today no provider holds that licence, so everyone is relying on the temporary rule that lets you keep an unlicensed provider while none is available. The moment the first licence is granted, the duty to migrate starts to bite in practice. We found no bill to replace the 2009 privacy law on official sources, checked on 18 August 2026.
Dormant switches to watch, each of which can move without consultation. One: the regulator can rewrite the approved-country list by a single deliberation, adding the United States or removing the United Kingdom. Two: any company can be designated vital infrastructure by the ministry coordinating its sector, secretly, which pulls it into the localisation regime. Three: the head of government can waive the Moroccan-ownership requirement for a cloud provider case by case, which is the only realistic path for a global provider. Four: the one-year retention period for technical data can be changed by regulation. Five: the national cyber authority can impose sector-specific security rules on vital infrastructures at their own cost. The decree entered into force when the qualification standard was published in the official gazette issue dated 21 August 2025, and the twenty-four month transition runs from that date.
Sources
- Official sourceDGSSI / Bulletin officiel n° 7380Décret n° 2-24-921, articles 17, 18 and 19 (transition, 24-month deadline, entry into force)
dgssi.gov.ma
“doivent se conformer aux dispositions du présent décret dans un délai maximum de vingt-quatre (24) mois à compter de la date de son entrée en vigueur”
Link checked 18 August 2026
- Official sourceDGSSI / Bulletin officielArrêté du Chef du gouvernement n° 3-17-25 du 1er août 2025 fixant le référentiel des exigences de qualification des prestataires de services Cloud, Bulletin officiel n° 7432 du 21 août 2025
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — list of qualified cloud providers, empty as at 18 August 2026
dgssi.gov.ma
“Aucun service disponible pour le moment.”
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — full list of legislative and regulatory texts in force
dgssi.gov.ma
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Loi n° 05-20 relative à la cybersécurité
Act of parliament · Dahir n° 1-20-69 du 25 juillet 2020, Bulletin officiel n° 6906 du 6 août 2020; décret d'application n° 2-21-406 du 15 juillet 2021
The hard wall. Sensitive data held by public bodies, and by any company the state has designated as vital infrastructure, must be hosted only in Morocco. The list of designated companies is secret by law. Hosting abroad is punished by a fine of up to 400,000 dirhams, about 44,000 United States dollars.
Enforced by General Directorate for Information Systems Security
Transfer model: Not allowed
What it makes you do
- Keep the data in the countrySensitive data must be hosted exclusively on national territory. Applies to state administrations, local authorities, public establishments and enterprises, other public-law bodies, and to designated vital infrastructures.
- Secure the data
- Appoint a data protection officerAn information systems security officer who is the national authority's contact point and must be independent.
- Independent auditSensitive systems must be audited by providers qualified by the national authority, at the operator's cost.
- Hold a security certificateEvery sensitive information system needs a formal security homologation before it goes live.
- Written vendor contractOutsourcing a sensitive information system requires a contract governed by Moroccan law, with protection, auditability and reversibility commitments.
- Report cyber incidentsDeclare incidents to the national authority as soon as you know.
What it costs if you get it wrong
- Fixed maximum fine: MAD 400,000 — about $44 thousandHosting sensitive data outside national territory
- Fixed maximum fine: MAD 200,000 — about $22 thousandFailure to declare a cyber incident
- Criminal liability: Doubled penalties on repeat offence within four yearsRepeat offence
Sources
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, articles 10 to 14, 19, 20, 25 and 49
dgssi.gov.ma
“Les données sensibles doivent être exclusivement hébergées sur le territoire national.”
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — sensitive information systems of vital infrastructures: classification, declaration and secrecy
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — legislative and regulatory texts, including décret n° 2-21-406 of 15 July 2021
dgssi.gov.ma
Link checked 18 August 2026
Décret n° 2-24-921 relatif au recours aux prestataires de services Cloud par les entités et les infrastructures d'importance vitale disposant de systèmes d'information ou de données sensibles
Directly binding regulation · Décret n° 2-24-921 du 22 octobre 2024, Bulletin officiel n° 7352 (arabe) et n° 7380 (français); arrêté n° 3-17-25 du 1er août 2025, Bulletin officiel n° 7432
Sensitive cloud work for public bodies and vital infrastructures must go to a cloud provider licensed by the national cyber authority, with the strictest licence demanding Moroccan ownership, Moroccan staff and processing only in Morocco. Nobody holds that licence yet, so a temporary rule allows unlicensed providers, with a hard migration deadline of 21 August 2027.
Enforced by General Directorate for Information Systems Security
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the country — from 21 August 2025Level 1 providers must place all hosting infrastructure in Morocco. Level 2 providers must process, run and store data exclusively in Morocco, and manage and supervise the service exclusively from Morocco.
- Prove the data stays under local controlLevel 2 also requires Moroccan majority ownership, Moroccan-national operating staff, and a ban on any other party accessing the customer's data without the customer's prior agreement. A waiver needs the head of government's prior agreement.
- Hold a security certificateProviders are qualified for a maximum of five years against a published requirements standard, and are audited by the national authority.
- Make switching cloud provider possibleOn exit the provider must hand back the systems and data, then certify their deletion.
- Assess high-risk projects — from 21 August 2025While no qualified provider exists, a documented risk and impact analysis is required before using an unqualified one, and migration is compulsory once a qualified provider appears.
- Independent audit
What it costs if you get it wrong
- Fixed maximum fine: MAD 400,000 — about $44 thousandRelated breaches of the cyber security law, including hosting sensitive data abroad and using unqualified providers for regulated services
Sources
- Official sourceDGSSI / Bulletin officiel n° 7380Décret n° 2-24-921, full text as published in the Bulletin officiel
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSI / Bulletin officielArrêté n° 3-17-25 du 1er août 2025 (Bulletin officiel n° 7432 du 21 août 2025), which triggered entry into force
dgssi.gov.ma
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — qualified cloud provider list, empty on 18 August 2026
dgssi.gov.ma
“Aucun service disponible pour le moment.”
Link checked 18 August 2026
Loi n° 05-20 relative à la cybersécurité, dispositions propres aux opérateurs
Act of parliament · Loi n° 05-20, articles 26 to 34 and 50
Telecoms operators, internet access providers, cyber security providers, digital service providers and internet platform publishers must keep connection records and logs for one year, follow the national cyber authority's directives, and warn customers about attacks. No rule found requiring that data to stay in Morocco, unless the operator is designated vital infrastructure.
Enforced by General Directorate for Information Systems Security
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep logs — 1 yearConnection data, computer logs and security-event traces. The period can be changed by regulation.
- Report cyber incidentsTell the national authority without delay about events that could affect customers' systems.
- Tell people what you doWarn customers about vulnerabilities or attacks affecting them.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: MAD 200,000 — about $22 thousandFailing the retention and directive obligations, or obstructing the national authority
Sources
- Official sourceDirection Générale de la Sécurité des Systèmes d'Information (DGSSI)Loi n° 05-20, articles 26 to 30 and 50
dgssi.gov.ma
“La durée de conservation des données techniques nécessaires à l'identification et à l'analyse de l'incident est fixée à une année.”
Link checked 18 August 2026
- Official sourceDGSSIDGSSI — texts including loi n° 24-96 on posts and telecommunications
dgssi.gov.ma
Link checked 18 August 2026
Directive n° 4/W/2022 fixant les règles minimales en matière d'externalisation vers le cloud par les établissements de crédit
Regulator directive · Bank Al-Maghrib, directive n° 4/W/2022 du 19 mai 2022
Banks and payment institutions may use foreign cloud, but outsourcing any significant function to the cloud needs Bank Al-Maghrib's prior agreement, and the bank must itself decide and enforce which countries may host its data. No Moroccan banking rule was found requiring the data to stay in the country.
Enforced by Bank Al-Maghrib
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision
What it makes you do
- Written vendor contractThe contract must fix data location by country or region, subcontracting limits, audit rights and an exit plan.
- Independent auditThe bank must be able to control and inspect outsourced functions, and Bank Al-Maghrib may access information about them at any time.
- Put a transfer safeguard in placeThe bank must police its cloud provider's compliance with the privacy law on transfers abroad and set the eligible hosting countries itself.
- Make switching cloud provider possibleA documented, tested exit strategy is required.
- Keep data for a minimum period — 10 yearsTen years for the documents behind customer accounts, and for payment institutions' transaction registers.
What it costs if you get it wrong
- Loss of your licenceSupervisory action by Bank Al-Maghrib for breach of prudential directives
Sources
- Official sourceBank Al-MaghribBank Al-Maghrib, Recueil des textes législatifs et réglementaires (updated to end 2023) — directive n° 4/W/2022, articles 8 to 14
bkam.ma
“Tout projet d'externalisation de l'établissement de ses fonctions significatives vers le cloud doit recueillir l'accord préalable de Bank Al-Maghrib.”
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Loi n° 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel
Act of parliament · Dahir n° 1-09-15 du 18 février 2009, Bulletin officiel n° 5714 du 5 mars 2009
Morocco's general privacy law. Data can go abroad only to one of 32 countries the regulator has approved, or with its written permission. Processing must be declared, and sensitive processing authorised, before it starts. Penalties are criminal, including prison, and fines double for companies.
Enforced by National Commission for the Control of the Protection of Personal Data
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Government sign-off needed, Explicit consent, Needed for a contract, Someone's life is at risk, Legal claims, Important public interest
What it makes you do
- Register or notifyEvery processing must be declared to the regulator; sensitive data, genetic data, criminal records, national identity numbers and file interconnections need prior authorisation.
- Appoint a local representativeRequired where the controller is not established in Morocco but uses means located there. The representative substitutes for the controller in all rights and duties.
- Tell people what you do
- Get consent
- Let people see their data
- Let people correct their data
- Let people object
- Secure the data
- Put a transfer safeguard in placeTransfer notice for approved destinations; written authorisation, decided within two months and extendable once, for all others.
- Delete data after a periodNo fixed period. Data may identify people only as long as the purpose requires.
What it costs if you get it wrong
- Criminal liability: 1 year imprisonment and MAD 200,000 — about $22 thousandTransferring personal data abroad in breach of the transfer rules
- Criminal liability: 1 year imprisonment and MAD 300,000 — about $33 thousandProcessing sensitive data without the required consent
- Fixed maximum fine: MAD 100,000 — about $11 thousandRunning a file without the required declaration or authorisation
- Fixed maximum fine: MAD 600,000 (fines doubled for companies) — about $66 thousandAny offence committed by a legal person; confiscation or closure of premises also available
- Order to stop: Temporary or permanent ban on processingRegulator order under its investigation powers
Sources
- Official sourceCommission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP)Loi n° 09-08, full text
cndp.ma
Link checked 18 August 2026
- Official sourceCNDPCNDP — transfer procedure and two-month decision period
cndp.ma
Link checked 18 August 2026
Délibération n° 236-2015 du 18 décembre 2015 portant modification de la délibération n° 465-2013 établissant la liste des Etats assurant une protection suffisante
Adequacy decision · CNDP, délibération n° 236-2015
The approved-destination list. Thirty-two countries are treated as offering sufficient protection, so data can go there on a notice rather than a permission. Croatia was never added, the United Kingdom is still on it, and the United States has never been on it.
Enforced by National Commission for the Control of the Protection of Personal Data
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Put a transfer safeguard in place32 approved countries: the European Union states except Croatia, plus Iceland, Liechtenstein, Norway, Switzerland, the United Kingdom and Canada. The United States is not listed.
Sources
- Official sourceCNDPDélibération CNDP n° 236-2015 du 18 décembre 2015
cndp.ma
Link checked 18 August 2026
- Official sourceCNDPCNDP transfer page, which still points to deliberation 236-2015 as the operative list
cndp.ma
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the 2015 approved-country list is still the current list, unamended.
The regulator's own transfer page still points to deliberation 236-2015, and no later amending deliberation was found. But the site publishes only a partial archive of deliberations, so a later amendment could exist without being visible.
Whether Morocco has ratified the modernised Convention 108+.
The regulator's own deliberation confirms accession to the original Council of Europe Convention 108 on 28 May 2019. Its page on Convention 108+ did not state a ratification date when fetched.
Telecoms-sector rules on where operator data must sit, and licence conditions.
The telecoms regulator's website was unreachable from outside Morocco on 18 August 2026, both through the fetch tool and directly.
That no insurance or securities data localisation rule exists.
We reviewed the regulators' published regulation indexes but did not read every circular in full. Recorded as no rule found, checked 18 August 2026, rather than as an absence.
General tax and commercial record retention floors.
The tax administration website returned an access-denied response. Only banking and payment retention periods are asserted here, from the central bank's own compendium.
Rules for online gambling, education technology and mapping or geospatial data.
No official Moroccan source located for these sectors within this research run.
The exact entry-into-force date of the cloud decree: 21 August 2025 or 29 August 2025.
The decree starts on the day the qualification standard is published in the official gazette. The gazette issue is dated 21 August 2025 but the cyber authority announced the publication on 29 August 2025. Plan to the earlier date, which makes the transition deadline 21 August 2027.
Whether a bill to replace or amend the 2009 privacy law is before parliament.
The government's general secretariat and parliament websites were unreachable or blocked during this run, so we can only say no bill was found on the regulator's own site.
Whether any cloud provider was qualified between the check on 18 August 2026 and publication.
The regulator's list is the authoritative source and it was empty when checked. It can be populated at any time without notice.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Morocco versus
Compare