Law 09-08 and the GDPR: what overlaps, and what does not substitute
Being GDPR-compliant does not make you compliant in Morocco, and the reverse is also true. The differences that matter in practice: prior formality, authority, transfers.
Two situations come up constantly. A Moroccan company working with European clients wonders whether the GDPR is enough. A subsidiary of a European group wonders whether its group compliance covers Morocco. The answer is the same in both directions: no, one does not replace the other, and the reason is structural.
The difference that changes the work: prior formality
This is the central point. The GDPR removed prior notification as a first-line requirement: you document internally (a register of processing activities, impact assessments) and answer if controlled. Law 09-08 keeps the prior formality: you declare — or apply for authorisation — before putting the processing into effect.
The concrete consequence: a company perfectly compliant with the GDPR can be in breach in Morocco simply because it has filed nothing. Its register is immaculate, its governance solid, and the receipt is missing. See the CNDP declaration.
What overlaps a great deal
- The principles — a determined purpose, data minimisation, accuracy, limited retention, security.
- Data subject rights — information, access, rectification, objection.
- The controller’s responsibility for its sub-processors.
- The reinforced regime for sensitive data, health first among them.
In other words: the technical work recycles very well. Role separation, logging, automatic purges, sub-processor agreements — what you did for the GDPR applies directly.
What does not recycle
- The filing — forms F211 / F115 / F112, specific to the CNDP.
- The competent authority — the CNDP, with its own deadlines: acknowledgement within 24 hours, two months extendable once for an authorisation.
- Transfers — a transfer outside Morocco is assessed under Moroccan law, not European mechanisms. Your standard contractual clauses are not a local free pass.
- The vocabulary of the file — GDPR documentation cannot be filed as-is; it has to be translated into declarable processing activities.
The case of a European group’s subsidiary
The pattern is almost always the same: the tools are the group’s, hosted in Europe, under group contracts. Three questions then arise, and none is settled by group compliance:
- Who is the controller for the Moroccan activity — the subsidiary or the parent?
- Are the locally operated activities declared to the CNDP?
- Is the flow into the group’s tools treated as a transfer, and does it appear in the file?
What we do with it
In practice we start from what exists: if there is a GDPR register it becomes the skeleton of the inventory; what is almost always missing is the qualification under the Moroccan regime and the technical part actually enforced. See CNDP compliance and sensitive data.
Related guides: consent, health data.
Related articles

Compliance & regulation
CNDP declaration: who must declare, what, and how
Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.

Compliance & regulation
Health data and the CNDP: prior authorisation, not declaration
Clinics, laboratories and health funds: health data falls under CNDP prior authorisation. What that changes in a project schedule and in the software.

Compliance & regulation
Consent to personal data in Morocco: collecting it, proving it, honouring withdrawal
Consent is not a checkbox: it is evidence you must keep and a withdrawal you must honour. What that means for a website, a form and a customer database.
Newsletter
Get our upcoming articles straight to your inbox.

