In short: in Morocco, every processing of personal data must be declared to the CNDP before it starts, and some processing needs prior authorisation (Law 09-08, art. 12). An HR file that holds national ID card (CIN) numbers needs authorisation. A transfer to a European parent company is still a formality to complete, even to a country the CNDP treats as adequate. Fines run from MAD 10,000 to MAD 300,000, most of them alongside a prison term of 3 months to 1 year, and are doubled for a company (arts. 52 to 64). Law as at 2 October 2026.
This article follows our general guide Data Protection and Privacy Law in Morocco. It deals with one question, the filings to make with the Commission nationale de contrôle de la protection des données à caractère personnel (CNDP): which regime applies, what goes in the file, how long it takes, and what an omission costs. It is written for legal, HR and data protection teams of groups with a subsidiary or branch in Morocco.
The default rule is prior declaration. Every processing must be declared to the CNDP before it is implemented, unless a specific law provides otherwise (Law 09-08, art. 12-2 and art. 14). Prior authorisation is required where the processing concerns any of the following (art. 12-1):
The CIN criterion is the one that most often surprises European groups. It moves a large share of HR files, customer files and visitor logs into the authorisation regime, files that would otherwise need only a declaration. The CNDP has in fact adopted a model authorisation request for access control to private business premises (deliberation no. D-943-2025 of 28 November 2025).
A declared processing can also be moved to authorisation. If the CNDP considers that it presents manifest dangers for privacy and fundamental rights, it may subject it to authorisation by a reasoned decision notified within 8 days of filing (art. 20).
For several common types of processing the CNDP has adopted deliberations that set a standard framework. Where a processing fits that framework, the company files a declaration or an authorisation request "in conformity with a decision", with an undertaking of compliance, instead of a free-form file. The CNDP publishes separate forms for each route (among them F-211 for an ordinary declaration, F-214 for a declaration in conformity with a decision, F-112 for an authorisation request and F-113 for an authorisation in conformity with a decision).
The declaration contains an undertaking that the processing will comply with the law (art. 13). It states in particular (art. 15):
In practice the CNDP also asks for the documents that prove what the declaration states: the information notice given to data subjects (art. 5), proof of consent or of the other legal ground relied on (art. 4), the processing agreement where a service provider handles the data (art. 23), and a signing authority. The CNDP states that incomplete files are rejected.
| Filing | Time limit | Source |
|---|---|---|
| Declaration, issue of the receipt | 24 hours; processing may start on receipt | Law 09-08, art. 19 |
| Decision to subject a declared processing to authorisation | 8 days from filing | Law 09-08, art. 20 |
| Authorisation request | 2 months, extendable once | Decree 2-09-165, art. 28 |
| Request to transfer data abroad | 2 months, extendable once | Decree 2-09-165, arts. 48 and 28 |
If the CNDP has not decided within the time limit, the authorisation is deemed granted (Decree 2-09-165, art. 28), and the same applies to transfer requests (art. 48). But the CNDP states that time limits run only from a complete file and that incomplete files are rejected. We therefore recommend waiting for a written decision or, failing that, keeping proof of the date on which the file was complete.
The references of the receipt or authorisation must then appear on collection and information documents (arts. 5 and 19). Any change to a declared processing, such as a new recipient or a new transfer, must be notified to the CNDP without delay (art. 15). For an authorised processing, any change to the information in the request requires a new request (Decree 2-09-165, art. 27). Changes to a transfer must be reported to the CNDP within 8 working days (Decree, art. 49).
The principle is in article 43. A controller may transfer personal data to a foreign state only if that state ensures a sufficient level of protection of privacy and fundamental rights. The law gives the CNDP the task of listing those states (art. 43, para. 3).
The list was set by CNDP deliberation no. 465-2013 of 6 September 2013, amended by deliberation no. 236-2015 of 18 December 2015. It includes, among others, Germany, Austria, Belgium, Spain, France, Italy, the Netherlands, Portugal, the United Kingdom, Switzerland and Norway. The United States is not on it, and neither is Croatia.
Being on the list does not remove the formality. The list applies subject to notifying each transfer to the CNDP under the appropriate regime, and the transfer must be stated in the declaration of the processing (art. 15-e). The CNDP grants a transfer authorisation only once the underlying processing has itself been declared or authorised, so the files have to be filed in sequence. A transfer within a group of companies, for the same categories of data and the same purposes, may be covered by a single joint declaration (Decree 2-09-165, art. 50).
To a country that is not on the list, article 44 allows the transfer in three cases:
For a group, the third route is the stable one. An intra-group transfer agreement or binding corporate rules, followed by a CNDP authorisation, give lasting cover to an HR system or hosting located outside the list, for example in the United States. Employee consent is a weak basis, because it must be express and can be withdrawn. For transfers in the other direction, from the EU to Morocco under the GDPR, see our guide Transferring Personal Data from the EU to Morocco.
HR management. The CNDP adopted deliberation no. 298-AU-2014 of 11 April 2014, which sets a model authorisation request for human resources management in the private sector. HR management therefore generally goes through an authorisation in conformity with that decision, not a simple declaration. The file includes the model employment contract with its personal data clause.
CCTV. Video surveillance is governed by deliberation no. 350-2013 of 31 May 2013. The accepted purpose is the security of property and people. Cameras must not be used to monitor one or more employees, and must not film places of worship, union premises, toilets, meeting rooms or break areas. Footage is kept for three months at most. A sign showing the CNDP receipt number must be displayed. A system that fits the deliberation is declared with an undertaking of compliance; a system that departs from it needs authorisation.
Biometrics. Biometric access control is governed by deliberation no. 478-2013 of 1 November 2013. It needs authorisation and is reserved for sensitive premises and installations with restricted access that represent a major security issue going beyond the organisation's own interest. The controller must explain why a less intrusive method is not enough. The system is used for authentication, not identification, in principle without a central database, with the data stored on a medium held by the person. Time and attendance tracking is not an accepted purpose for biometrics.
Whistleblowing. Whistleblowing schemes are governed by deliberation no. 351-2013 of 31 May 2013. They are declared with an undertaking of compliance with that deliberation.
Vehicle geolocation. We could not confirm on the CNDP's website the number of a deliberation specific to geolocation of employees. Without a verified standard framework, the processing follows the general rules: declaration, or authorisation if the file holds CIN numbers (art. 12), prior information of employees (art. 5) and a retention period limited to what the purpose requires (art. 3).
The timetable below is a practice estimate built on the official time limits set out above.
| Step | Indicative duration |
|---|---|
| Inventory of processing and choice of regime (art. 12) | 2 to 4 weeks |
| Preparing documents: information notices, employment contracts, processing agreements, intra-group agreement | 2 to 6 weeks |
| Declarations | receipt within 24 hours, then 8 days during which the CNDP may require authorisation |
| Authorisations, including HR and biometrics | 2 months, extendable once (the decree does not fix the length of the extension) |
| Transfer outside the list, after the filing for the underlying processing | 2 months, extendable once |
For a subsidiary that sets up its HR file and shares it with a parent company using a provider outside the list, we see four to eight months in total in practice. The transfer authorisation cannot be granted before the filing for the main processing.
| Article | Offence | Penalty |
|---|---|---|
| 51 | Processing that harms security, public order or morality | withdrawal of the receipt or authorisation by the CNDP |
| 52 | Processing without declaration or authorisation, or continued after withdrawal | fine of MAD 10,000 to 100,000 |
| 53 | Refusal of access, rectification or objection rights | fine of MAD 20,000 to 200,000 per offence |
| 54 to 56 | Unfair collection, misuse of purpose, excessive retention, processing without a legal ground | 3 months to 1 year imprisonment and/or MAD 20,000 to 200,000 |
| 57 | Sensitive data without express consent; data on offences | 3 months to 1 year and/or MAD 50,000 to 300,000 |
| 58 | Missing the security measures of articles 23 and 24 | 3 months to 1 year and/or MAD 20,000 to 200,000 |
| 60 | Transfer in breach of articles 43 and 44 | 3 months to 1 year and/or MAD 20,000 to 200,000 |
| 61 | Misuse of data or disclosure to unauthorised third parties, even through negligence | 3 months to 1 year and/or MAD 20,000 to 200,000 |
| 62 | Obstructing CNDP inspections | 3 to 6 months and/or MAD 10,000 to 50,000 |
| 63 | Refusing to apply CNDP decisions | 3 months to 1 year and/or MAD 10,000 to 100,000 |
Where the offender is a legal person, fines are doubled, without prejudice to the penalties its managers face. The legal person also faces one of the following penalties: partial confiscation of its assets, confiscation under article 89 of the Penal Code, or closure of the establishment or establishments where the offence was committed (art. 64). A repeat offence of the same nature within a year of a final conviction doubles the penalties again (art. 65). Commissioned and sworn CNDP agents record offences in reports sent to the public prosecutor within 5 days (art. 66).
The texts in force remain Law 09-08 and its implementing Decree no. 2-09-165, supplemented by CNDP deliberations. The CNDP adopted new deliberations on 28 November 2025, including deliberation no. D-939-2025 on the simplified declaration of cookies. A rewrite of the law to bring it closer to the GDPR has been discussed for several years; to our knowledge, no text replacing it had been published in the Bulletin officiel at the date of this article.
This article sets out the law in force on 2 October 2026. It is not legal advice.
A note on how this works in practice. The CNDP examines files against its own forms and expectations, which change by deliberation. A file prepared abroad from the text of the law alone often comes back with requests for more documents. Having it reviewed in Morocco before filing is the simplest way to keep to the timetable.