Business Law16 min read

Cybersecurity and Corporate Legal Liability in Morocco: What Businesses Really Risk

By Salma Tazi

Legal Editor — Family Law

Published on
Cybersecurity and Corporate Legal Liability in Morocco: What Businesses Really Risk

When a data breach becomes a court case in Morocco

A Casablanca e-commerce company receives a registered letter from the Commission Nationale de contrôle de la protection des Données à caractère Personnel, better known as the CNDP. The managing director first assumes that it is a routine administrative request. It is not. A customer has complained about unsolicited marketing messages, the company’s customer database has never been declared, and its privacy notice consists of two vague lines copied from a foreign website.

The director’s reaction is familiar: panic, followed by disbelief. He had invested in advertising, delivery software and an outsourced cloud platform, but nobody had told him that collecting names, telephone numbers, addresses and purchasing histories constituted regulated processing under Moroccan law. The company had passwords and antivirus software. It did not have legal compliance.

This is a composite case based on situations regularly encountered in practice; identifying details have been changed. It illustrates a wider problem highlighted by Moroccan reporting, including Challenge coverage of citizens being on the front line of cybercrime: the first victim may be the customer, but the business holding the data will quickly be asked what it did to prevent the incident.

There is no need to invent a spectacular national incident figure to understand the risk. Public alerts from the Direction Générale de la Sécurité des Systèmes d’Information, or DGSSI, show a persistent exposure to phishing, ransomware, account compromise and vulnerabilities affecting widely used systems. Published statistics do not always cover the same reporting perimeter, and many private-sector incidents are never publicly disclosed. Any single number should therefore be read with caution.

Cybersecurity is no longer an issue that a director can leave entirely to the IT technician. It is a matter of corporate governance, contractual liability, personal data protection, criminal evidence and financial survival. If your company manages a customer file, employee records, CCTV footage, a loyalty application or online payments, the real question is not whether Moroccan cyber law concerns you. It is whether you can prove compliance when a regulator, customer, insurer or prosecutor asks.

Why Moroccan directors still underestimate legal liability

Morocco’s economic fabric is dominated by small and medium-sized businesses, many of them family-controlled. Agreements with software vendors are sometimes concluded orally, by purchase order or through a one-page quotation. Access rights remain active after employees leave, backups are connected permanently to the main network, and customer spreadsheets circulate through personal messaging accounts. This is convenient until something goes wrong.

Large banks, telecom operators and listed groups tend to have structured compliance departments. The gap is much wider among TPEs and SMEs. Yet Law No. 09-08 does not create a general exemption simply because a company has twenty employees rather than two thousand. Legal responsibility follows the processing and the risk, not the sophistication of the organisation.

The Moroccan legal framework for cybersecurity and personal data

Law No. 09-08: the central pillar of personal data protection

The principal text is Law No. 09-08 relating to the protection of individuals with regard to the processing of personal data, promulgated by Dahir No. 1-09-15 of 18 February 2009 and published in Official Bulletin No. 5714 of 5 March 2009. It should be read alongside its implementing decree and the CNDP’s deliberations.

Contrary to a common citation error, the definition of the data controller appears in Article 1 of Law No. 09-08, not Article 3. In practical terms, the controller is the person or body that determines the purposes and means of processing. If your company decides why customer data is collected and how it will be used, your company is normally the controller, even where the database is hosted by an external IT provider.

Article 3 lays down essential data-quality principles. Personal data must be processed fairly and lawfully, collected for specified, explicit and legitimate purposes, remain adequate and not excessive, be accurate, and be kept no longer than necessary for the relevant purpose. These rules directly affect CRM databases, recruitment files, payroll records, CCTV archives and digital marketing campaigns.

Under Article 23 of Law No. 09-08, the controller must implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access, particularly where processing involves transmission over a network.

This is the provision that turns weak cybersecurity into a legal problem. Article 23 does not impose one universal product or certification. It demands measures appropriate to the risks. A court or the CNDP may therefore examine access controls, encryption, patch management, backups, staff training, incident response and the supervision of vendors.

Articles 12 to 18 organise prior formalities. Depending on the processing, a company may need a declaration, an authorisation or another legally applicable procedure. The distinction matters. Processing involving sensitive information, biometric identifiers, health data or other specially regulated categories cannot be treated like an ordinary supplier directory.

The CNDP has not simply disappeared or been formally renamed out of existence. In 2026, the familiar statutory institution remains the Commission Nationale de contrôle de la protection des Données à caractère Personnel. Government reform projects or broader digital-governance discussions should not be confused with a completed legislative renaming.

Law No. 05-20 on cybersecurity

Law No. 05-20 on cybersecurity was promulgated by Dahir No. 1-20-69 of 30 July 2020. Its implementation is supported by Decree No. 2-21-406. The law structures national cybersecurity governance and establishes enhanced obligations for public administrations, public bodies, infrastructures of vital importance and operators of information systems of vital importance, commonly referred to as SIIV.

For an operator falling within this perimeter, cybersecurity is not voluntary good practice. Requirements may concern security policies, risk assessment, system approval, audits, the use of qualified or approved providers, and the reporting of incidents to the competent authority. The exact obligation depends on the entity’s classification and the measures adopted by the competent authorities.

Most ordinary Moroccan SMEs are not automatically SIIV operators. That does not make Law No. 05-20 irrelevant. A software company, call centre, maintenance contractor or cloud provider serving a bank, hospital, telecom operator or strategic public body may inherit demanding security duties through procurement documents and contracts. A failure can then lead to termination, indemnification claims, exclusion from future tenders and, where the statutory conditions are met, regulatory consequences.

Cybercrime under Articles 607-3 to 607-11 of the Criminal Code

Law No. 07-03 introduced offences concerning automated data-processing systems into the Moroccan Criminal Code. The operative provisions are generally cited as Articles 607-3 to 607-11. They punish conduct such as fraudulent access to an automated system, remaining in it without authority, interference with system operation, fraudulent alteration or deletion of data, computer-related forgery and the use or provision of instruments intended to commit such offences.

The exact penalty depends on the act, its consequences and any aggravating circumstances. The statutory scale can rise from short custodial sentences and fines for basic unauthorised access to several years’ imprisonment and substantially higher fines for interference, falsification or attacks affecting sensitive systems. It is therefore inaccurate to treat every employee data leak as an automatic offence under Article 607-7. Article 607-7 principally concerns attempts; the prosecutor must identify the correct substantive offence, and other provisions on professional secrecy, theft, breach of trust, fraud or unfair disclosure may also be relevant.

The Consumer Protection Act and online customers

Law No. 31-08 enacting consumer protection measures adds another layer, particularly for distance selling and e-commerce. A business must give consumers clear information and honour its contractual commitments. A misleading privacy statement, an insecure purchasing process or the misuse of customer data may support claims based on consumer law, Law No. 09-08 and the Dahir forming the Code of Obligations and Contracts.

Morocco does not yet have a literal domestic copy of the EU General Data Protection Regulation. The expression “Moroccan GDPR equivalent” is useful commercially, but legally imprecise. The Moroccan regime is Law No. 09-08. A Moroccan company may nevertheless be directly subject to the EU GDPR under Article 3(2) where it offers goods or services to people in the European Union or monitors their behaviour there. A Moroccan processor working for an EU controller will also face detailed contractual obligations under Article 28 GDPR.

The CNDP’s real powers: a notice is not the same as a criminal conviction

What the CNDP can investigate

The CNDP is established and governed by Articles 27 and following of Law No. 09-08. It receives formalities, examines complaints, issues opinions and deliberations, verifies compliance and may carry out investigations within its legal powers. Where facts may constitute an offence, the matter can be referred to the competent prosecutorial authority.

A typical case may begin with a complaint from a customer or employee. The CNDP asks the controller for explanations and supporting documents: the declaration receipt, legal basis, information notice, consent evidence where consent is relied upon, security policy, retention period, service-provider contract and records of how an access or deletion request was handled. The company is then expected to answer within the period stated in the correspondence.

A CNDP formal notice is not itself a criminal judgment. Equally, it should never be ignored. Failure to respond, obstruction or continuation of unlawful processing can worsen the company’s position and lead to referral to the public prosecutor. The criminal court, not the CNDP acting alone, imposes imprisonment.

Deadlines and practical cost of responding

There is no safe universal rule that every CNDP notice always grants thirty or sixty days. The enforceable deadline is the one stated in the notice or applicable decision. In practice, remediation projects are often organised over several weeks, but urgent measures—stopping an unlawful campaign, disabling compromised accounts or suspending an insecure transfer—may need to be taken immediately.

For a straightforward SME, legal remediation after a notice may cost roughly MAD 15,000 to MAD 40,000. If the company needs penetration testing, access redesign, encryption, backup separation, contractual renegotiation and forensic work, the total can reach MAD 80,000 or more. These are market estimates, not official tariffs.

In one anonymised Rabat matter, a service business was able to document its processing, correct its customer notice, complete the appropriate CNDP formalities and rewrite its vendor contract in approximately forty-five days. The decisive factor was not a perfect historical record—it did not have one—but a rapid, evidenced and legally coherent response led by management.

Criminal sanctions under Law No. 09-08

The penal provisions are found in Articles 51 to 61 of Law No. 09-08. They cover distinct misconduct, including obstruction of the CNDP, carrying out regulated processing without the required formality, unlawful processing of protected categories, failure to respect individual rights, security-related breaches and unlawful transfers. Depending on the offence, fines run through bands extending from tens of thousands of dirhams up to MAD 300,000, and certain offences can carry imprisonment.

It is risky to state that every data leak automatically produces a MAD 300,000 fine or two years in prison. The prosecution must establish the elements of a specific offence. Repetition and the rules governing legal persons can increase financial exposure, while directors or employees may be prosecuted where their own conduct satisfies the offence.

If your company receives a complaint or formal notice, an attorney for personal data protection in Morocco should review the response before it is filed. A hurried admission written by a technician may later be used in regulatory, civil or criminal proceedings.

Civil liability after a customer data breach

Articles 77 and 78 of the Code of Obligations and Contracts

A victim can seek damages independently of CNDP action. The ordinary legal basis is found in Articles 77 and 78 of the Dahir forming the Code of Obligations and Contracts, known as the DOC. Article 77 addresses intentional conduct that unlawfully causes material or moral harm. Article 78 establishes liability for harm caused by fault, including imprudence or negligence.

In practical terms, a claimant must normally establish three elements: a fault attributable to the defendant, actual and certain damage, and a causal link between that fault and the damage.

The fault may consist of storing passwords in plain text, allowing former staff to retain access, ignoring known vulnerabilities, failing to supervise a processor or collecting more information than necessary. A breach of Article 23 of Law No. 09-08 can reinforce evidence of fault, but the claimant must still prove compensable damage and causation.

Article 88 of the DOC, concerning responsibility for things in one’s custody, is sometimes discussed in technology disputes. Its application to an information system is not automatic and should not replace the more direct analysis under Articles 77, 78 and the contract. Counsel must examine who controlled the system and what actually caused the loss.

Who can sue, and before which Moroccan court?

Customers, employees, business partners and, in appropriate circumstances, competitors may seek compensation. The competent court depends on the parties and the legal character of the dispute. A dispute between merchants arising from a commercial contract may go before the Commercial Court of Casablanca or another territorially competent commercial court. An individual consumer’s tort or contractual claim is not automatically commercial merely because the defendant is a company; the tribunal of first instance may be competent.

Appeals may be brought before the relevant court of appeal or commercial court of appeal, followed by a possible appeal on points of law to the Cour de cassation. Published Moroccan case law specifically quantifying mass personal-data breach damages remains limited. It would be misleading to cite an unidentified Casablanca judgment as a settled national precedent. Courts tend to assess demonstrated financial loss, identity fraud, business interruption, reputational injury and moral harm case by case.

Your IT provider does not automatically carry the whole risk

“The cloud provider lost the data, so it is their problem.” This sentence is heard often, and it is legally dangerous. The company that determines the purpose of the customer database generally remains the controller under Article 1 of Law No. 09-08. Outsourcing hosting does not outsource accountability to customers or the CNDP.

The controller may later bring a contractual claim against the provider if the provider breached a security commitment, professional duty or service-level agreement. Success depends heavily on the written contract. Moroccan businesses are frequently weakened by vague quotations that say nothing about incident notification, evidence preservation, backups, subcontracting, data location or liability caps.

Every significant technology agreement should address security standards, role allocation, confidentiality, access management, audit rights, incident notification, business continuity, return and deletion of data, subcontractors and indemnification. Obtain specialist support for the drafting of an IT contract with data-security clauses. A clause requiring notification “without delay” should also define contacts, minimum information and escalation procedures.

Seven minimum cybersecurity obligations for a Moroccan company

1. Map and lawfully formalise personal-data processing

Start with an inventory: whose data do you hold, why, where, who can access it, to whom is it transferred, and when is it deleted? Then determine the applicable CNDP formality under Articles 12 to 18 of Law No. 09-08. Not every operation follows the same procedure, and CNDP deliberations may simplify or exempt narrowly defined routine processing. An exemption must be verified; it should never be assumed.

2. Apply purpose limitation and retention periods

Article 3 prohibits indefinite storage simply because storage is cheap. Payroll documents, unsuccessful job applications, CCTV recordings, inactive customer accounts and marketing leads need documented retention rules. Legal retention duties under tax, labour, accounting or anti-money-laundering rules must, of course, be reconciled with data-protection requirements.

3. Give people clear information and respect their rights

Law No. 09-08 gives data subjects rights including information, access, rectification and opposition, subject to statutory conditions and exceptions. Your website, forms, employment documents and call-centre scripts should identify the controller, purpose, recipients and rights. A privacy notice is not valid simply because it mentions the word “confidential”.

4. Implement security under Article 23

At a minimum, review multi-factor authentication, privileged accounts, updates, endpoint protection, encrypted backups, network segmentation, logging, physical access and employee departures. ISO/IEC 27001 is not universally mandatory for Moroccan SMEs, but it offers a useful risk-management benchmark. The appropriate measure depends on the sensitivity and volume of data.

5. Control vendors and cross-border transfers

Know where your provider stores data. A foreign SaaS subscription may involve a cross-border transfer requiring examination under Law No. 09-08 and CNDP procedures. Vendor due diligence should continue after signature through audit evidence, security reports and incident exercises.

6. Prepare an incident-response plan

Law No. 09-08 does not contain a general seventy-two-hour breach-notification rule identical to Article 33 GDPR for every Moroccan SME. Do not invent one. Notification obligations can nevertheless arise from Law No. 05-20 for entities within its scope, sectoral regulation, CNDP conditions, contracts or the GDPR where applicable. A company should pre-identify its decision team so that lawyers, technicians, management and communications staff do not contradict one another during a crisis.

7. Preserve evidence and train employees

Most attacks involve a human decision somewhere: a malicious attachment, reused password, fraudulent payment request or unauthorised export. Training should be documented and repeated. Logs, forensic images and relevant emails must be preserved in a manner that supports authenticity and chain of custody if a complaint is filed.

Obligations by company profile

  • TPE and ordinary SME: Law No. 09-08 formalities, clear notices, rights procedures, proportionate security, vendor contracts and an incident plan.
  • Larger company or sensitive-data operator: enhanced governance, regular testing, dedicated compliance ownership, stronger encryption, documented risk assessments and legal review of transfers.
  • SIIV or critical-sector operator: all relevant data-protection duties plus Law No. 05-20, DGSSI and sector-specific requirements, including applicable audits and incident reporting.
  • Bank or credit institution: additional prudential and information-system security expectations issued by Bank Al-Maghrib, including applicable directives and supervisory requirements.

Is a data protection officer mandatory?

Moroccan Law No. 09-08 does not impose a universal DPO obligation equivalent to Articles 37 to 39 GDPR. Appointment is nevertheless sensible for businesses processing sensitive or high-volume data, and an EU-facing Moroccan company may need a DPO under the GDPR’s own criteria. The role may be internal or outsourced, but it needs independence, resources and access to management.

The European NIS and NIS2 directives have not been transposed into Moroccan law as domestic directives. Their influence is still visible in international contracts, supply-chain assessments and the National Cybersecurity Strategy 2030. This is the practical meaning of the connection between the European NIS framework and Moroccan digital compliance.

Criminal liability of directors and employees

Can a director be prosecuted personally?

A cyberattack against a company does not automatically make its director a criminal. Criminal liability requires a legal offence and evidence that the person participated in it or personally failed to perform a duty whose breach is punishable. The corporate form is not a magic shield, however. A director who knowingly orders unlawful collection, conceals evidence, obstructs the CNDP or continues prohibited processing may face personal exposure.

The distinction between the liability of the legal person and that of the individual must be examined offence by offence. A prosecutor will look at delegations of authority, internal warnings, budgets, prior incidents, minutes and who made the decision. This is why cybersecurity reports sent to management should produce documented action rather than silence.

Employees, insiders and serious misconduct

An employee who copies a customer database for a competitor may face criminal investigation under the provisions corresponding to the actual conduct: fraudulent system access or interference, breach of trust, theft-related offences, professional secrecy or other applicable rules. The facts should not be forced into Article 607-7, which addresses attempts relating to preceding computer offences.

Employment consequences are separate. Article 39 of the Moroccan Labour Code lists forms of serious misconduct that may justify dismissal, including disclosure of a professional secret causing prejudice to the enterprise. The employer must still follow the disciplinary procedure, notably the employee hearing safeguards under Article 62 of the Labour Code. Calling conduct “gross misconduct” in a termination letter does not remove the need for proof and procedure.

Ransomware, phishing and extortion

A ransomware attack may involve several cumulative offences: fraudulent access under the computer-crime provisions, damage to data, and extortion under Article 538 of the Moroccan Criminal Code where the legal elements are satisfied. The commonly repeated reference to Article 364 for ransomware extortion is incorrect; Article 538 is the relevant starting point for extortion analysis.

Do not pay a ransom impulsively. Payment does not guarantee restoration, may expose the company to repeated demands, and can create sanctions, anti-money-laundering or criminal-financing concerns depending on the recipient. Management should obtain legal, forensic and insurance advice before any decision.

How to file a cybercrime complaint in Morocco

  1. Contain the incident without unnecessarily destroying evidence. Disconnect affected systems where appropriate, reset compromised credentials from clean devices and preserve logs.
  2. Contact a qualified incident-response provider and, where relevant, the DGSSI ecosystem or maCERT channels identified through official sources.
  3. Prepare a factual chronology: first alert, systems affected, accounts used, ransom messages, payments attempted and data potentially accessed.
  4. File a complaint with the police or Royal Gendarmerie according to territorial competence, or submit it to the competent public prosecutor. Major and organised cases may involve specialised cybercrime units of the judicial police, including the BNPJ.
  5. Preserve digital evidence using forensic copies and documented handling. Screenshots alone are useful but may not be sufficient.
  6. Assess notifications to the CNDP, DGSSI, sector regulator, insurer, contracting partners and affected individuals according to the laws and contracts actually applicable.

For ordinary misdemeanours, Article 5 of the Moroccan Code of Criminal Procedure generally establishes a four-year limitation period, subject to interruption, suspension, reclassification and special rules. The often-quoted five-year period is not the current general Moroccan rule for délits. Urgent filing remains advisable because digital evidence disappears quickly.

Where management or an employee is under investigation, seek criminal defence in a cyberattack or hacking case before giving a detailed technical statement. Morocco’s accession to the Budapest Convention also facilitates international cooperation in cross-border cybercrime matters, although obtaining foreign-held evidence can still take months.

Cyber-risk insurance in Morocco

What a cyber policy may cover

The Moroccan cyber-insurance market is developing, with coverage available through insurers and specialised brokers, sometimes as a standalone policy and sometimes as an extension. Product names and underwriting appetites change, so businesses should obtain current written terms rather than rely on a general statement that a particular insurer always offers the same cover.

Typical guarantees may include forensic investigation, crisis management, legal expenses, data restoration, business interruption, third-party cyber liability and notification costs. Indicative annual premiums for an SME can range from approximately MAD 5,000 to MAD 50,000, but businesses with sensitive data, weak controls or high turnover may pay much more or be refused.

Insurers usually ask about multi-factor authentication, backups, patching, remote access, CNDP compliance and previous incidents. Answer accurately. A materially false declaration may jeopardise coverage under Moroccan insurance law and the policy terms.

Read exclusions before signing

Common exclusions concern known vulnerabilities, deliberate acts by senior management, war or state-backed events, failure to maintain declared controls and pre-existing incidents. Criminal fines and custodial penalties cannot simply be transferred to an insurer. Regulatory fines may also be excluded or uninsurable, depending on their nature and applicable public policy.

Ask the broker for a comparison of sub-limits, waiting periods, deductibles, ransomware conditions, panel providers and business-interruption calculations. A cyber policy does not replace compliance. In fact, weak compliance may be the reason the insurer refuses to pay.

How to achieve Law No. 09-08 compliance step by step

Step 1: Conduct a processing audit

The first question I ask a new business client is simple: “Show me every place where personal data enters the company.” The answer usually reveals web forms, WhatsApp accounts, spreadsheets, CCTV, HR software, paper files and vendor platforms that management had forgotten. Create a practical processing register even though Law No. 09-08 does not reproduce the GDPR’s register obligation word for word for every controller.

Step 2: Determine the CNDP procedure

For each operation, identify whether it is covered by a declaration, prior authorisation, specific CNDP decision or a valid exemption. The starting point is Articles 12 to 18 and the CNDP’s current forms and deliberations. Sensitive processing should never be launched on the assumption that silence equals approval. Administrative timelines depend on the procedure, completeness of the file and requests for further information.

Forms and guidance are available from cndp.ma. Keep receipts, decisions and the exact version of the processing description filed. If the purpose later changes substantially, review whether an updated formality is required.

Step 3: Implement technical and organisational measures

Prioritise the highest risks: administrator accounts, exposed remote access, unpatched servers, unencrypted laptops, shared passwords and backups connected to the production environment. For a Moroccan SME, a meaningful initial technical programme may cost MAD 20,000 to MAD 100,000, depending on existing infrastructure. Buying tools without assigning responsibility is rarely effective.

Step 4: Rewrite legal documents and contracts

Update website privacy information, customer forms, employee notices, internal IT rules and vendor agreements. Employment monitoring must be transparent, proportionate and compatible with workplace rights. Marketing consent should not be hidden inside general terms that no customer can understand.

Contracts should state which party is the controller or service provider, define instructions, require confidentiality, regulate subcontracting and provide rapid incident notice. Avoid unlimited promises that the technical team cannot fulfil, but do not accept a provider clause excluding all liability while your company remains exposed to customers.

Step 5: Train, test and document

Run phishing exercises, restore backups, test escalation contacts and simulate a weekend ransomware attack. Directors should participate. A response plan known only to the IT manager is useless when that manager is unavailable.

A legal and technical compliance project for a medium-sized SME commonly takes three to six months. A straightforward legal package may begin around MAD 15,000 to MAD 40,000, while a combined legal, governance and technical programme can reach MAD 30,000 to MAD 150,000 or more. Scope, sensitivity, number of sites and legacy systems determine the real cost.

An attorney specialising in cybersecurity in Casablanca can coordinate the legal audit, CNDP correspondence, IT contracts and litigation strategy. The lawyer should work with forensic experts rather than pretend to replace them. Conversely, a technician should not make legal admissions or decide notification duties alone.

What to do during the first 24 hours of a ransomware attack

  1. Activate the incident team and appoint one decision-maker.
  2. Isolate affected equipment, but do not wipe it before forensic preservation.
  3. Protect clean backups and verify whether attackers reached identity systems or cloud accounts.
  4. Involve legal counsel early so that regulatory, contractual and evidential issues are assessed alongside recovery.
  5. Notify the insurer within the policy deadline and obtain approval before appointing providers if required.
  6. File a criminal complaint with a clear evidence package.
  7. Assess personal-data impact: categories, number of people, encryption status, exfiltration evidence and possible harm.
  8. Communicate truthfully. Do not announce that no data was stolen before forensic analysis supports that conclusion.

Concretely, speed matters, but disciplined speed matters more. Disconnecting the wrong server, deleting logs or sending inconsistent notices can increase civil and criminal exposure. Keep a decision log recording who authorised each action and why.

Cybersecurity compliance is an investment, not administrative decoration

The risk faced by a Moroccan company is cumulative. The CNDP may investigate compliance. A prosecutor may examine an offence. Customers or partners may claim damages under Articles 77 and 78 of the DOC. An insurer may dispute coverage, while the company suffers downtime and reputational damage.

The most exposed businesses share the same weaknesses: no processing map, no reliable backups, excessive access rights, undeclared processing and IT contracts concluded through informal exchanges. By contrast, a company that can produce its CNDP records, security policies, training evidence, audit reports and incident chronology is in a far stronger legal position, even when an attack succeeds.

Future reforms may bring Moroccan law closer to GDPR standards and deepen alignment with international supply-chain rules influenced by NIS2. Companies should also monitor the National Cybersecurity Strategy 2030, DGSSI measures and sectoral instructions. Waiting for a new statute is not a defence to existing obligations under Law No. 09-08, Law No. 05-20, the Criminal Code and the DOC.

Compliance can become a competitive advantage in public tenders, bank financing, outsourcing and European partnerships. If your business is based near the capital or serves public-sector and regulated clients, a cybersecurity law firm in Rabat can review public-law and regulatory requirements. More broadly, every director should obtain legal advice for a Moroccan company facing digital risks before the registered letter, ransom note or customer lawsuit arrives.

This article provides general legal information as of September 2026. It is not a substitute for advice based on the facts, sector and current official texts applicable to a particular company.

Frequently Asked Questions

Must every Moroccan company register with the CNDP?
Most companies processing personal data must first examine the formalities established by Articles 12 to 18 of Law No. 09-08. Depending on the operation, this may involve a declaration, prior authorisation or a CNDP exemption or simplified regime; the company itself is not registered through one universal procedure. Sensitive, biometric, health-related or specially regulated processing usually requires closer scrutiny and may require prior authorisation. Operating without the required formality can expose the controller to the penal provisions in Articles 51 to 61.
What are the concrete sanctions for a data leak in Morocco?
A leak does not trigger one automatic fine, because liability depends on the underlying failures and the offence proven. Under Articles 51 to 61 of Law No. 09-08, relevant offences can carry fines ranging through several statutory bands up to MAD 300,000, and some can include imprisonment. The CNDP may investigate and refer suspected offences to the public prosecutor, while customers can separately claim damages under Articles 77 and 78 of the DOC. Contractual claims, reputational loss and business interruption may cost substantially more than the statutory fine.
Does the EU GDPR apply to Moroccan companies?
The GDPR is not Morocco’s domestic data-protection law; that role belongs to Law No. 09-08. However, Article 3(2) GDPR may apply directly to a Moroccan company offering goods or services to people in the European Union or monitoring their behaviour there. Moroccan processors handling data for EU businesses also commonly assume Article 28 GDPR duties through contract. Exporters, call centres, SaaS providers and outsourcing companies may therefore need simultaneous Moroccan and European compliance.
What should a Moroccan company do after a ransomware attack?
Immediately isolate affected systems where technically appropriate, protect clean backups and preserve forensic evidence rather than wiping every machine. Engage incident-response specialists and legal counsel, notify the cyber insurer within the policy deadline, and file a complaint with the competent police, Royal Gendarmerie or public prosecutor. Assess whether personal data was accessed or exfiltrated and whether notification is required under Law No. 05-20, sectoral rules, CNDP conditions, contracts or the GDPR. Do not pay the ransom without legal, sanctions and forensic advice.
Is my IT provider responsible if customer data is stolen?
Not automatically. Under Article 1 of Law No. 09-08, the company deciding the purposes and means of the customer-data processing will generally remain the controller, even where an external provider hosts the system. The company may bring a contractual or civil claim against a negligent provider, but the result depends on evidence and the security, audit, notification, subcontracting and liability clauses in the contract. Outsourcing infrastructure does not, by itself, outsource accountability.
How much does Law No. 09-08 compliance cost for a Moroccan SME?
For an SME with twenty to fifty employees and no unusually sensitive processing, a legal compliance project may cost approximately MAD 15,000 to MAD 40,000. Technical remediation such as multi-factor authentication, encryption, access redesign, secure backups and testing may add MAD 20,000 to MAD 100,000 or more. A combined programme often runs for three to six months and may total MAD 30,000 to MAD 150,000 depending on complexity. These are indicative professional-market estimates, not CNDP tariffs.
Can an employee be personally prosecuted for causing a data leak?
Yes, if the employee’s conduct satisfies a criminal offence such as fraudulent access, data interference, breach of trust or unlawful disclosure under the applicable provisions. Articles 607-3 to 607-11 of the Criminal Code address offences against automated data-processing systems, but Article 607-7 should not be misdescribed as a general insider-disclosure offence because it principally concerns attempts. The employee may also face disciplinary action, including possible dismissal for serious misconduct under Article 39 of the Labour Code. The employer must still respect the hearing procedure in Article 62.
What does Law No. 05-20 change for Moroccan businesses?
Law No. 05-20 creates a structured cybersecurity regime, with particularly demanding obligations for public bodies, infrastructures of vital importance and operators of information systems of vital importance. Depending on classification and implementing measures, duties may include risk management, security approval, audits, incident reporting and compliance with DGSSI requirements. An ordinary SME is not automatically an SIIV operator. Nevertheless, suppliers to banks, telecom operators, hospitals and strategic public entities often inherit these standards contractually.
How should I choose a cybersecurity lawyer in Casablanca or Rabat?
Morocco does not have a separate bar membership reserved exclusively for cybersecurity lawyers, so examine actual experience rather than titles. Ask whether the lawyer has handled CNDP formalities or notices, IT contracts, personal-data audits, cybercrime complaints and business-criminal matters. The lawyer should also be able to work with forensic and security specialists while preserving legal strategy and evidence. Request a written scope, fee estimate, conflict check and realistic remediation timetable before instructing the firm.

Recommended lawyers

Speak with a lawyer specialized on these topics

Maitre HANANA ABDERRAHIM

Maitre HANANA ABDERRAHIM

Cabinet Me. Maitre HANANA ABDERRAHIMRabat
Droit bancaire & financierReal Estate LawTax Law+15
French · Arabic
Direct contact only
Sofia Bousselham
9 years of experience

Sofia Bousselham

Laya Law FirmCasablanca

Avocate au barreau de Casablanca, Sofia Bousselham accompagne depuis plus de neuf ans entreprises et particuliers dans la sécurisation de leurs activités et la résolution de leurs litiges. Trilingue (français, arabe, anglais), elle intervient tant en conseil qu’en contentieux. Sa pratique se concentre sur le droit social, le droit des sociétés, le droit commercial, la propriété intellectuelle et la protection des données personnelles. À l'écoute et pragmatique, elle privilégie une approche personnalisée et stratégique, alliant rigueur juridique et compréhension des enjeux business de ses clients.

Labor LawBusiness LawIntellectual Property+13
French · Arabic · English
Direct contact only