Key takeaways: Morocco's position as a nearshoring hub for European tech, telecom, and BPO operations rests on a maturing but fast-moving regulatory framework. Companies building cloud infrastructure, deploying AI, or providing outsourced engineering services from Morocco must navigate overlapping Moroccan laws and, increasingly, extraterritorial EU rules. This guide maps the key regimes.
Morocco's telecommunications sector is governed by Law No. 24-96 on postal and telecommunications services, promulgated in 1997 and amended several times, most recently by Law No. 121-12 in 2019. [1] [2] The Agence Nationale de Réglementation des Télécommunications (ANRT), created in 1998 under this law, is the sector regulator responsible for licensing, spectrum management, interconnection, and competition oversight. [3] [4]
Law 24-96 establishes a two-tier authorization regime. Full telecom operators — those establishing and operating public telecommunications networks — require a licence granted by ANRT under detailed specifications (cahier des charges). [5] Internet access providers (ISPs), by contrast, are not classified as telecom operators and need only file a declaration with ANRT, although they remain subject to the general obligations of Law 24-96. [6] Operating a telecommunications network without a licence carries penalties of one month to two years' imprisonment and fines of MAD 10,000 to MAD 200,000 under Article 83. [7]
VoIP services occupy a legal grey area. ANRT's general manager issued a decision on 6 April 2004 ruling that VoIP calls require a telecommunications licence under Article 2 of Law 24-96. [8] However, commentators note that Law 24-96 was drafted in the mid-1990s and was not designed to govern over-the-top internet services, making enforcement against OTT providers and VPN users legally questionable. [9] There is no dedicated MVNO regulatory framework; virtual operators must negotiate access through commercial agreements with licensed network operators under ANRT oversight.
Under the Maroc Digital 2030 strategy, Morocco has set a timeline for 5G introduction: 25% territorial coverage by 2026 and 70% by 2030. [10] The 2030 FIFA World Cup co-hosting has accelerated the process, and ANRT is preparing specifications for 5G licence allocation, including a planned Neutral Host model for venues such as stadiums. [11] [12] [13]
Morocco's data protection regime is anchored in Law No. 09-08 on the protection of individuals with regard to the processing of personal data, enforced by the Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel (CNDP). [14] All data processing must be declared to the CNDP before it begins; sensitive data, biometric data, and database interconnections require prior authorization rather than simple notification. [15]
Under Articles 43 and 44 of Law 09-08, personal data may only be transferred to a foreign country if that country ensures an adequate level of protection, as assessed by the CNDP. [16] In the absence of adequacy, a transfer requires prior CNDP authorization, which may be granted where sufficient safeguards exist, such as standard contractual clauses or binding corporate rules. [17] Critically, Morocco does not yet hold an EU GDPR adequacy decision, although it ratified Council of Europe Convention 108 in September 2019 and is working toward Convention 108+. [18] [19] The CNDP recognizes a limited list of adequacy-recognized jurisdictions including the EU, Switzerland, Canada, Iceland, Norway, and Liechtenstein. [20] Non-compliance exposes companies to administrative fines of MAD 10,000 to MAD 300,000 per violation and up to two years' imprisonment. [21]
Decree No. 2-24-921 establishes a qualification framework for cloud service providers handling sensitive information systems under Law 05-20. [22] The framework operates on two levels: Level 1 qualification is required when responsible entities and critical infrastructure rely on cloud services to host or manage sensitive information systems. Level 2 imposes additional legal and technical conditions and is mandatory for handling sensitive data — ensuring that such data is processed on infrastructures controlled by entities exclusively subject to national legislation. [23] Hyperscaler deployments (AWS, Azure, foreign SaaS) hosting Moroccan government or critical-infrastructure data must comply with this framework.
Law No. 05-20 on cybersecurity, promulgated in 2020, prescribes security rules for state administrations, public institutions, and operators of vital infrastructure (OIVs) with sensitive information systems. [24] [25] [26] The Direction Générale de la Sécurité des Systèmes d'Information (DGSSI), Morocco's national cybersecurity authority operating under the National Defense Administration, enforces the law and the DNSSI implementing directive. [27] [28]
Key obligations for OIVs include: maintaining an inventory of information systems available to the DGSSI, undergoing audits of sensitive systems at least once every two years by DGSSI-qualified auditors, appointing a dedicated information systems security officer (RSSI), and developing business continuity and disaster recovery plans. [29] [30] [31] [32] Telecom operators, ISPs, cybersecurity service providers, digital service providers, and online platform providers are also subject to obligations under Law 05-20. [33] Penalties for non-compliance can reach MAD 1 million. [34]
Morocco does not yet have a specific AI law, but the framework is rapidly being built. [35] The "Maroc IA 2030" roadmap, launched following the National Artificial Intelligence Conference of July 2025, targets Morocco's position as a regional AI hub, focusing on data sovereignty, skills development, and AI integration across key sectors. [36] [37] A National Agency for AI Governance is anticipated in late 2026, and a rollout of National Sovereign Cloud Architecture will introduce new compliance requirements for AI developers regarding data residency. [38] [39] The CNDP issued a March 2025 communiqué signaling that AI processing requires specific attention to transparency, fairness, and non-discrimination principles under existing Law 09-08. [40]
Under Article 2(1)(c), the EU AI Act applies to providers and deployers of AI systems located in a third country where the output produced by the AI system is used in the Union. [41] This has direct consequences for Moroccan nearshoring and BPO vendors serving EU clients.
Nearshoring vendors must address EU AI Act risk allocation in their service agreements. Key provisions should clarify: whether the Moroccan vendor is acting as a provider or deployer; who bears the cost of conformity assessment and registration for high-risk systems; allocation of the authorized-representative obligation; and how GPAI model documentation and copyright compliance responsibilities flow between parties. Where a deployer substantially modifies a high-risk AI system or affixes its name to it, it becomes a provider and must assume provider obligations. [48]
Law No. 43-20 on trust services for electronic transactions, in force since 13 July 2023, repeals and replaces Law 53-05 on the electronic exchange of legal data. [49] [50] [51] Inspired by the EU eIDAS regulation, it recognizes three levels of electronic signature — simple, advanced, and qualified — as well as electronic seals, timestamps, and registered delivery services. [52] [53] [54] The DGSSI is now the national authority for trust services (replacing ANRT in this role), responsible for approving qualified trust service providers (PSCos). [55] A qualified electronic signature carries the same legal effect as a handwritten signature.
*This guide is for informational purposes only and does not constitute legal advice. Regulatory developments in Morocco are ongoing — companies should seek qualified counsel before making compliance decisions.*The practice guide is ready in the draft panel. It covers all requested topics — telecom licensing under Law 24-96, the ANRT licence/declaration distinction, VoIP/OTT and MVNO positioning, the 2024–2026 5G reforms, Law 09-08 and CNDP data protection obligations, cross-border transfers and Morocco's EU adequacy status, the sovereign cloud/DGSSI qualification framework under Decree 2-24-921, Law 05-20 cybersecurity requirements, Morocco's Maroc IA 2030 strategy, the EU AI Act's extraterritorial reach (Article 2(1)(c), provider/deployer/GPAI duties), contractual allocation guidance for BPO agreements, and Law 43-20 e-signature/trust services — closing with a compliance checklist table. Specific statutory provisions are cited throughout in web-format H2/H3 structure, with no client names.