Law 09-08 and the GDPR: what overlaps, and what does not substitute
Being GDPR-compliant does not make you compliant in Morocco, and the reverse is also true. The differences that matter in practice: prior formality, authority, transfers.
Two situations come up constantly. A Moroccan company working with European clients wonders whether the GDPR is enough. A subsidiary of a European group wonders whether its group compliance covers Morocco. The answer is the same in both directions: no, one does not replace the other, and the reason is structural.
The difference that changes the work: prior formality
This is the central point. The GDPR removed prior notification as a first-line requirement: you document internally (a register of processing activities, impact assessments) and answer if controlled. Law 09-08 keeps the prior formality: you declare — or apply for authorisation — before putting the processing into effect.
The concrete consequence: a company perfectly compliant with the GDPR can be in breach in Morocco simply because it has filed nothing. Its register is immaculate, its governance solid, and the receipt is missing. See the CNDP declaration.
What overlaps a great deal
- The principles — a determined purpose, data minimisation, accuracy, limited retention, security.
- Data subject rights — information, access, rectification, objection.
- The controller’s responsibility for its sub-processors.
- The reinforced regime for sensitive data, health first among them.
In other words: the technical work recycles very well. Role separation, logging, automatic purges, sub-processor agreements — what you did for the GDPR applies directly.
What does not recycle
- The filing — CNDP-specific forms: F211 and F214 for the prior declaration (normal or simplified), F112 and F113 for the prior-authorisation request (normal or simplified).
- The competent authority — the CNDP, with its own deadlines: receipt of a declaration within 24 hours, eight days in which the CNDP may move the processing to prior authorisation, two months extendable once only for an authorisation decision. An incomplete file starts none of these periods running until the CNDP has received the documents it asked for.
- Transfers — a transfer outside Morocco is assessed under Moroccan law, not European mechanisms. Your standard contractual clauses are not a local free pass.
- The vocabulary of the file — GDPR documentation cannot be filed as-is; it has to be translated into declarable processing activities.
The case of a European group’s subsidiary
The pattern is almost always the same: the tools are the group’s, hosted in Europe, under group contracts. Three questions then arise, and none is settled by group compliance:
- Who is the controller for the Moroccan activity — the subsidiary or the parent?
- Are the locally operated activities declared to the CNDP?
- Is the flow into the group’s tools treated as a transfer, and does it appear in the file?
What we do with it
In practice we start from what exists: if there is a GDPR register it becomes the skeleton of the inventory; what is almost always missing is the qualification under the Moroccan regime and the technical part actually enforced. See CNDP compliance and sensitive data.
Related guides: consent, health data.
Related articles

Compliance & regulation
CNDP forms: which one applies to your processing
F211, F214, F112, F113, F115: five forms, two regimes, and a choice that follows from your processing inventory — not from your preference.

Compliance & regulation
Video surveillance and the CNDP: what law 09-08 requires
Installing cameras is a processing of personal data. What has to be declared, what has to be displayed, and the questions that decide which regime applies.

Compliance & regulation
CNDP declaration: who must declare, what, and how
Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.
Newsletter
Get our upcoming articles straight to your inbox.

