Morocco Law 09-08 on Personal Data Protection + National AI Strategy 2030: AI Compliance Requirements
Morocco's Law 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data (2009) and its implementing Decree No. 2-09-165 govern automated processing of personal data including AI systems. The Commission Nationale de contrôle de la Protection des Données à caractère Personnel (CNDP) is the enforcement authority. On 2025-03-18 the CNDP publicly announced it has INITIATED work toward a formal deliberation on AI processing — an international benchmark, consultation with foreign DPAs, and hearings with national/international experts and stakeholders — not yet a finalized AI-specific rule. Separately, in January 2026, Morocco launched its national AI roadmap "Maroc IA 2030", which aligns AI governance with UNESCO recommendations and the EU AI Act; a National Agency for AI Governance is anticipated in late 2026, with the CNDP overseeing the data-protection aspects of AI in the interim. Organizations processing personal data of Moroccan residents through AI must file a CNDP declaration (or, for high-risk/sensitive-data processing, obtain prior CNDP authorization). Morocco is a key hub for EMEA operations and data flows under EU adequacy discussions.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
February 18, 2009
Fine-only tier (Art. 52, missing declaration/authorization): 10,000-100,000 DH (20,000-200,000 DH for a legal entity, doubled per Art. 64), no imprisonment. General processing-violation tier (Arts. 54-56, 58-61: fraudulent collection, unauthorized retention/purpose, missing security, unauthorized cross-border transfer, negligent misuse): 3 months-1 year imprisonment and/or 20,000-200,000 DH (up to 400,000 DH fine for a legal entity). Sensitive-data tier (Art. 57 — most relevant to AI profiling using racial/ethnic, political/religious, union, or health data without express consent): 3 months-1 year imprisonment and/or 50,000-300,000 DH (up to 600,000 DH for a legal entity, ~$60,000 USD at 2026 rates) — CYCLE 18 (2026-08-22) CORRECTION: previously stated as a mandatory "AND" combination; the statutory text (Art. 57: "...et d'une amende de 50.000 à 300.000 dirhams ou de l'une de ces deux peines seulement") makes imprisonment and the fine ALTERNATIVE penalties at the court's discretion, exactly like the Arts. 54-61 tier already correctly phrased with "and/or" in this same entry — the inconsistency was an internal contradiction, not just an external-source gap. Recidivism (Art. 65) doubles sanctions again.
What Your Business Must Do
3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
File CNDP Declaration for AI-Powered Automated Processing
High PriorityMorocco Law 09-08 (Article 12) requires organizations to file a declaration with the CNDP before commencing automated processing of personal data, including AI systems. High-risk processing (sensitive data, surveillance, profiling) requires prior CNDP authorization (not just declaration). File at cndp.ma.
Implement AI Transparency for Moroccan Users
Medium PriorityCNDP guidance and Morocco's National AI Strategy 2030 require organizations to disclose when AI is making or significantly influencing decisions affecting individuals. Automated decisions must be explainable and subject to human review on request. Document AI decision pathways for any system affecting Moroccan residents. Sensitive data used in AI profiling (health, racial/ethnic, political/religious, union-membership inferences) without express consent triggers Law 09-08's highest penalty tier (Article 57).
Comply with Morocco Cross-Border Transfer Rules
Medium PriorityMorocco Law 09-08 (Articles 43-45) restricts transfers of Moroccan personal data outside Morocco to countries with adequate protection. AI systems that process Moroccan data in cloud infrastructure outside Morocco must document adequacy or obtain CNDP authorization for the transfer. Morocco has bilateral adequacy with EU under EU-Morocco Association Agreement discussions.
Who Does This Apply To?
Applies to any organisation processing the personal data of Moroccan residents through automated means, including AI systems — Morocco's Law 09-08 (2009) and its implementing Decree No. 2-09-165 are enforced by the CNDP. In scope: any organisation conducting automated processing of personal data (Article 12 requires filing a CNDP declaration before processing begins; high-risk processing involving sensitive data, surveillance, or profiling requires prior CNDP authorization — not merely a declaration), AI systems making or significantly influencing decisions about individuals (decisions must be explainable and subject to human review on request), and cross-border transfers of Moroccan data to AI infrastructure abroad (Articles 43-45 require adequacy or CNDP authorization). Maximum exposure is tiered (Law 09-08 Chapter VII, Arts. 51-66): fine-only for missing declaration/authorization (10,000-100,000 DH), 3 months-1 year imprisonment plus 20,000-200,000 DH for general processing violations, and the highest tier — 3 months-1 year imprisonment plus 50,000-300,000 DH — for processing sensitive data without express consent (Art. 57), with all fines DOUBLED where the violator is a legal entity (Art. 64).
Recent Regulatory Guidance
CNDP press release — "IA et protection des données à caractère personnel" (March 18, 2025)
The CNDP publicly confirmed that AI processing using personal data is governed by Law 09-08, and that a formal deliberation ("délibération") on AI processing is being worked toward — not yet finalized. The CNDP conducted an international benchmark and consulted foreign data-protection authorities, and announced it will hold hearings with national and international experts, scientific and professional organizations, institutions, and civil-society associations (stakeholders could register interest via auditions-ia@cndp.ma). No enforcement action, fine, or named company was referenced in this release — as of this date the CNDP was still in the consultation phase toward its first AI-specific rule.
Morocco "Maroc IA 2030" National AI Roadmap (launched 2026)
Morocco launched its national AI roadmap "Maroc IA 2030" (branded "AI Made in Morocco") in January 2026, operationalizing the outcomes of the National AI Conference held in July 2025. The roadmap aligns AI governance with UNESCO recommendations and the EU AI Act and sits alongside Digital Morocco 2030. A National Agency for AI Governance is anticipated in late 2026 to register and audit high-risk AI systems; in the interim, the CNDP oversees the data-protection aspects of AI under Law 09-08 (declaration/authorization for automated processing). Organizations operating in Morocco should implement CNDP-compliant data governance as a baseline ahead of forthcoming risk-based AI rules.
Frequently Asked Questions
Does Morocco Law 09-08 on Personal Data Protection + National AI Strategy 2030 apply to my business?
Morocco's Law 09-08 on the Protection of Individuals with Regard to the Processing of Personal Data (2009) and its implementing Decree No. 2-09-165 govern automated processing of personal data including AI systems. The Commission Nationale de… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Morocco Law 09-08 on Personal Data Protection + National AI Strategy 2030 is: Fine-only tier (Art. 52, missing declaration/authorization): 10,000-100,000 DH (20,000-200,000 DH for a legal entity, doubled per Art. 64), no imprisonment. General processing-violation tier (Arts. 54-56, 58-61: fraudulent collection, unauthorized retention/purpose, missing security, unauthorized cross-border transfer, negligent misuse): 3 months-1 year imprisonment and/or 20,000-200,000 DH (up to 400,000 DH fine for a legal entity). Sensitive-data tier (Art. 57 — most relevant to AI profiling using racial/ethnic, political/religious, union, or health data without express consent): 3 months-1 year imprisonment and/or 50,000-300,000 DH (up to 600,000 DH for a legal entity, ~$60,000 USD at 2026 rates) — CYCLE 18 (2026-08-22) CORRECTION: previously stated as a mandatory "AND" combination; the statutory text (Art. 57: "...et d'une amende de 50.000 à 300.000 dirhams ou de l'une de ces deux peines seulement") makes imprisonment and the fine ALTERNATIVE penalties at the court's discretion, exactly like the Arts. 54-61 tier already correctly phrased with "and/or" in this same entry — the inconsistency was an internal contradiction, not just an external-source gap. Recidivism (Art. 65) doubles sanctions again.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Morocco Law 09-08 on Personal Data Protection + National AI Strategy 2030?
The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://www.cndp.maLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan