Morocco’s digital health shift: a legal test for patient rights
Imagine a patient in Béni Mellal who develops chest pain and books a video appointment with a cardiologist based in Casablanca. The consultation takes place through a private application. The doctor sends an electronic prescription, but the patient’s local pharmacy cannot authenticate it. Two days later, the patient is admitted to hospital with a serious cardiac complication. Who is responsible: the doctor, the application operator, the data host, or perhaps nobody because the consultation took place through a screen?
This is no longer a theoretical question. The generalisation of Assurance Maladie Obligatoire, the reform of Morocco’s national health system launched following the Royal orientations of 2021, and the rapid adoption of remote services after Covid-19 have all accelerated digital healthcare. Hospitals are computerising patient files. Laboratories transmit results electronically. Doctors exchange scans through professional platforms—and, sometimes, through ordinary messaging applications that were never designed to protect medical confidentiality.
Yet one point must be corrected from the outset. Morocco does not operate in a complete legal vacuum. Telemedicine is already recognised by Law No. 131-13 on the practice of medicine, particularly Articles 99 to 102, and by Decree No. 2-18-378 of 25 July 2018 on telemedicine, subsequently amended in 2021. Personal health data are also protected by Law No. 09-08. What remains incomplete is the construction of a coherent digital health ecosystem covering interoperability, electronic medical records, secure hosting, patient identification, platform governance and modern cybersecurity obligations.
Public announcements concerning a broader digital health bill, including reports discussed by Medias24 and presentations associated with the Ministry of Health and Social Protection, must therefore be distinguished from enacted law. In Morocco, a project does not become enforceable merely because it has been presented publicly. It must be adopted, promulgated by dahir and published in the Bulletin Officiel. Its decrees may then be needed before several provisions can work in practice.
So what are the concrete telemedicine rights of patients in Morocco today? What may an electronic health record contain? Can an insurer or employer access it? And what remedies exist when a digital medical service causes harm? The answers lie at the intersection of medical law, personal-data protection, civil liability and criminal law.
The law applicable before any new digital health statute
Law No. 09-08: the foundation of medical data protection in Morocco
Law No. 09-08 on the protection of individuals with regard to the processing of personal data remains the central text for medical data protection in Morocco. It was promulgated by Dahir No. 1-09-15 of 18 February 2009 and published in the Bulletin Officiel No. 5744.
Article 1 defines personal data broadly and places information concerning health among sensitive data. This includes obvious information such as diagnoses, prescriptions and laboratory results, but also data that indirectly disclose a person’s physical or mental condition. A heart-rate history collected by a connected watch, a fertility calendar, a disability indicator or repeated visits to an oncology clinic may all reveal health information.
Article 4 of Law No. 09-08: personal data may, as a principle, be processed only where the data subject has unambiguously consented, subject to the statutory exceptions provided by the law.
Consent is not the only possible legal basis. Processing may also be justified by legal obligations, vital interests, the delivery of healthcare under conditions protecting professional secrecy, or other statutory grounds. Nevertheless, a clinic cannot treat the patient’s signature on a general admission form as unlimited permission to sell, advertise or disclose medical information.
Article 3 requires data to be processed fairly and lawfully, collected for specific and legitimate purposes, and kept relevant rather than excessive. Articles 7 and 8 organise the rights of access and rectification. Article 12 places sensitive-data processing, including many health-data operations, under a system of prior authorisation by the Commission Nationale de contrôle de la protection des Données à caractère Personnel, commonly known as the CNDP.
Security and confidentiality are equally central. A hospital or platform must adopt technical and organisational measures suited to the sensitivity of the information. In plain terms, storing thousands of medical records in an unencrypted spreadsheet, allowing staff to share one password, or sending psychiatric reports through an unsecured public link may constitute more than poor management. It may amount to unlawful processing and support a claim for compensation if harm results.
Law No. 131-13 already gives telemedicine a legal basis
It is sometimes said that Moroccan law does not recognise online medical consultations. That statement is outdated. Articles 99 to 102 of Law No. 131-13 expressly address telemedicine. Article 99 describes telemedicine through acts performed remotely using information and communication technologies, including diagnosis, preventive or post-therapeutic monitoring, specialist opinions, therapeutic decisions, prescriptions and surveillance of a patient’s condition.
Article 100 subjects telemedicine activities to an organised framework, while Articles 101 and 102 refer to the applicable conditions and regulatory implementation. Decree No. 2-18-378 of 25 July 2018 supplied operational rules and was adjusted during the pandemic period. This regulatory history matters because emergency practices tolerated during Covid-19 should not automatically be confused with the permanent legal regime.
A video call is therefore not outside medical law merely because the doctor and patient are in different cities. The practitioner remains bound by professional competence, independence, confidentiality, record-keeping and continuity-of-care duties. Remote practice must also be medically appropriate. A doctor who continues a teleconsultation despite symptoms requiring palpation, an electrocardiogram or immediate emergency referral may incur liability for failing to recognise the limits of distance care.
Law No. 131-13 also regulates medical practice more generally, including registration with the Moroccan Order of Physicians and the conditions under which medicine may be exercised. This becomes particularly sensitive when a Moroccan patient uses a platform to consult a foreign doctor who is not authorised to practise in Morocco.
The medical code of ethics does not stop at the edge of a screen
The Moroccan Code of Medical Ethics, historically based on the Dahir of 20 February 1953 and the professional rules administered by the Order, requires respect for human dignity, professional independence and medical secrecy. Its principles apply whether information is exchanged in a consulting room, by telephone or through an application.
The doctor must confirm the patient’s identity, obtain sufficient clinical information, explain the limits of the remote assessment and preserve a usable medical record. The practitioner must also avoid conducting a digital consultation in an environment where third parties can overhear confidential information. The same caution applies to the patient’s side: if relatives are present, their role and the patient’s agreement should be clarified.
Article 446 of the Moroccan Criminal Code punishes doctors, surgeons, health officers, pharmacists, midwives and other persons who disclose secrets entrusted to them because of their profession, except in situations where the law requires or permits disclosure.
Medical secrecy is therefore both an ethical and a criminal obligation. It covers the diagnosis, but also the fact that a person consulted a doctor, underwent a test or received a particular medicine.
Electronic medical records: legal rules exist, but the status remains fragmented
Moroccan healthcare establishments increasingly use electronic files, yet there is still no single, fully operational national regime answering every question concerning the electronic medical record in Morocco. Rules are dispersed across Law No. 09-08, healthcare legislation, professional secrecy, hospital procedures, CNDP authorisations and contractual arrangements with technology providers.
This fragmentation creates practical problems. Who determines the retention period? Can the patient download the complete record in a reusable format? Must one clinic transfer it to another? How are access logs preserved? Can a patient hide one episode of care from certain professionals? A future digital health statute should address these matters expressly rather than leaving them to incompatible software systems.
What a broader Moroccan digital health law is expected to organise
A unique health identifier
A proposed unique health identifier in Morocco would attach a stable number to each patient and allow records created by different providers to be matched correctly. Its principal benefit is clinical. Emergency physicians could identify allergies, pharmacists could detect dangerous interactions, and patients would not need to repeat the same imaging examination simply because two hospitals use different systems.
There are risks, however. A universal identifier can become a key capable of connecting medical, insurance, employment and administrative databases. The law must therefore prohibit use outside healthcare and clearly defined public-health purposes. Authentication should not rely on the identifier alone, and every consultation of the file should leave a trace showing who accessed what, when and for which purpose.
The patient should be able to view this access history and report suspicious consultations. A laboratory receptionist, for example, should not have the same access rights as an oncologist treating the patient. This is the principle of least privilege: each user sees only what is necessary for his or her duties.
The electronic medical record: contents and patient access
A national digital record may contain medical history, allergies, prescriptions, vaccination information, biological results, radiology reports, hospital discharge documents and care plans. But “may contain” should never mean “accessible to everyone in the health sector.” The sensitivity of a psychiatric report or HIV result is not identical to that of an ordinary appointment confirmation.
A credible statute must specify the professionals who may enter or consult information, the conditions for emergency access, the retention periods and the patient’s right to obtain a copy. It should also explain how contested information is corrected without erasing the clinical history. If a patient disputes a diagnosis, the original entry may need to remain traceable while a correction or second opinion is attached.
France offers one comparative model through its shared medical record and its certification regime for health-data hosts. Morocco can learn from that experience without copying it mechanically. Local implementation must account for rural healthcare, uneven internet access, Arabic and Amazigh language needs, and the large number of patients who rely on basic mobile phones rather than recent smartphones.
Secure hosting and transfers outside Morocco
Health-data hosting in Morocco is one of the most important—and least visible—issues. A consultation may appear Moroccan because the doctor and patient are in Rabat, while the video stream, appointment database and uploaded scans are stored on servers in Europe, North America or elsewhere.
Transfers abroad are regulated by Law No. 09-08, notably Article 43 and the following provisions. They cannot be treated as ordinary technical details hidden in lengthy terms of use. The controller must verify the legal conditions for transfer, obtain the necessary CNDP approval where required, and ensure an adequate level of protection or another legally accepted safeguard.
A future accreditation system for health-data hosts should require encryption, strong authentication, backup plans, access logging, incident response and regular independent audits. It should also define subcontractor liability. A clinic cannot escape its obligations merely by saying that “the cloud provider lost the file.”
Explicit recognition of different digital medical acts
Moroccan law already recognises telemedicine, but more detailed rules are needed to distinguish teleconsultation, tele-expertise between professionals, remote monitoring, medical assistance and digitally assisted diagnosis. Each activity presents different risks.
A teleconsultation involves a direct doctor-patient relationship. Tele-expertise may occur without the patient being online, when one physician asks another to review imaging or pathology results. Remote monitoring may continuously collect data from a pacemaker or glucose sensor. The law must determine who monitors alerts and how quickly action must be taken. Otherwise, patients may reasonably believe that their device is supervised around the clock when nobody is actually watching the dashboard.
Fundamental patient rights in a digital environment
Informed consent requires more than clicking “I agree”
Informed consent for teleconsultation in Morocco must be genuine. A pre-ticked box beneath twenty pages of terms is not enough for a medical decision. The patient should understand the identity and professional status of the practitioner, the purpose of the remote act, its limitations, the data collected, the persons who may receive them and the available alternative of an in-person examination.
Consent to healthcare and consent to data processing are related but distinct. A patient may accept a remote consultation without agreeing that the platform use consultation history for targeted advertising. Likewise, consent to share a scan with a second specialist does not authorise disclosure to an insurance broker.
The doctor should explain when distance itself creates a risk. For chest pain, severe abdominal symptoms, neurological deficits, breathing difficulties or a medical emergency, referral to an in-person service may be essential. The record should mention that explanation and the patient’s response.
Access, rectification and opposition
Articles 7 and 8 of Law No. 09-08 establish rights of access and rectification. A patient may ask whether personal data are being processed, obtain intelligible information about those data and request correction, updating, blocking or deletion where information is inaccurate or unlawfully processed.
A practical request should be sent to the hospital director, clinic manager or designated data controller by registered letter with acknowledgment of receipt, or through another channel that provides evidence of delivery. Include proof of identity, identify the treatment period and specify whether you require consultation records, prescriptions, imaging reports, access logs or information about recipients.
Be careful with the frequently repeated claim that Law No. 09-08 always gives the establishment exactly 30 days to answer. The statute’s provisions distinguish access and rectification mechanisms, and Article 8 includes a shorter operational period for carrying out justified rectification. The applicable period should therefore be checked against the precise request, CNDP rules and any sector-specific text. A controller should in all cases respond without unjustified delay.
If there is no satisfactory answer, the patient may file a complaint with the CNDP. Patients in public hospitals may also invoke Law No. 31-13 on access to information for administrative documents, although medical confidentiality, third-party privacy and the special rules governing personal data still apply.
Who may access the digital medical record?
The starting principle is simple: medical confidentiality remains the rule. Treating professionals may share information necessary for coordinated care under legally appropriate conditions. This does not give every employee of a hospital, CNSS office, insurance company or technology contractor unrestricted access.
An AMO managing body or medical adviser may process information required to assess entitlement and reimbursement, but only within the limits of the applicable legal mandate. An employer has no right to obtain an employee’s diagnosis or open the employee’s electronic medical record. Occupational physicians themselves are bound by secrecy and normally communicate conclusions about fitness for work, not the underlying diagnosis.
Private insurers should receive medical information only on a valid legal basis and within the limits of necessity and proportionality. An excessively broad consent clause deserves scrutiny, particularly where refusing it would make access to a contract impossible. Unauthorised disclosure may trigger civil liability, CNDP proceedings and criminal prosecution under Article 446 of the Criminal Code.
The boundary between health and wellness data also requires attention. Suppose a fitness application transfers biometric readings to an insurer that then modifies a premium. Calling the application a “wellness service” does not automatically remove the information from Law No. 09-08 when the readings reveal health status.
Continuity of digital care
Patients have a legitimate expectation that digital tools will not interrupt treatment. A platform should explain what happens if the video connection fails, how urgent symptoms are handled, whether prescriptions remain accessible and how follow-up questions are managed. There should also be a clear method for transferring the clinical report to the patient’s treating physician.
Digital care must never become a way to avoid physical examination when one is necessary. Nor should a platform disappear overnight while retaining records that patients need for ongoing treatment.
Liability of doctors and digital health platforms
Medical liability during a teleconsultation
The ordinary principles of Moroccan civil liability apply to remote medicine. Articles 77 and 78 of the Dahir forming the Code of Obligations and Contracts, commonly called the DOC, govern liability for intentional acts, faults, imprudence and negligence that cause harm.
Articles 77 and 78 of the DOC: a person whose act, fault, imprudence or negligence causes damage to another may be required to compensate that damage, provided that fault, harm and causal connection are established.
Medical liability is traditionally analysed as an obligation of means, not a guarantee of cure. The physician must provide conscientious and attentive care consistent with established scientific knowledge and the circumstances. Telemedicine does not reduce that standard. It changes the circumstances in which the standard is assessed.
A court may ask whether a remote consultation was suitable, whether the doctor collected adequate history, whether warning signs were recognised, whether an in-person examination was ordered and whether the prescription was safe. The patient generally needs to establish fault, damage and causation, often through a court-appointed medical expert.
If an artificial-intelligence tool suggests an incorrect treatment, the doctor who adopts the recommendation cannot simply blame the algorithm. A decision-support tool normally does not replace professional judgment. The software developer or platform may also be liable if a defect, misleading presentation or corrupted dataset contributed to the injury, but establishing this technical chain will require expert evidence.
Readers seeking a broader explanation can consult our page on how to engage a doctor’s liability in Morocco and the legal framework for healthcare in Morocco.
Platform and hosting-provider liability
The platform may be contractually liable where it promises secure transmission, appointment management, authentication or data availability and fails to deliver those services. Articles 230 and 231 of the DOC are relevant to contractual performance: valid contractual obligations bind the parties, and non-performance may result in liability subject to the legal conditions.
Law No. 53-05 on the electronic exchange of legal data is also relevant to electronic writings, signatures and evidential reliability. It should not, however, be misdescribed as a complete liability code for health platforms. A dropped connection does not automatically create liability under Law No. 53-05. The claimant must identify the breached duty and connect the technical failure to actual harm.
Law No. 43-20 on trust services for electronic transactions must also be considered for modern electronic trust services. In the case of an electronic prescription, evidential questions include the doctor’s identity, the integrity of the document, the reliability of the signature process and whether the document was altered after issuance.
Consider a falsified electronic prescription. If the doctor’s password was negligently shared, professional responsibility may arise. If the application allowed alteration without detection, the operator may be liable. If the hosting provider suffered an avoidable security breach, its role must be examined. More than one defendant may be involved; digital medicine often creates a chain of responsibility rather than a single responsible actor.
Why platform accreditation matters
A serious health-platform regulation in Morocco should require prior authorisation or accreditation based on technical security, governance, insurance coverage, professional supervision and business-continuity plans. Accreditation should be renewable and supported by audits rather than granted once for the lifetime of a company.
Patients should be able to identify the legal entity operating the service, its Moroccan contact details, the supervising medical professional, the location of data storage and the applicable complaints process. An application that conceals these details behind an app-store page presents an immediate warning sign.
The CNDP and health data governance
CNDP powers and their practical limits
The CNDP supervises compliance with Law No. 09-08. It receives declarations and authorisation applications, examines complaints, conducts investigations and controls processing activities. It may issue formal positions and refer criminal offences to the competent authorities.
One point needs legal precision. The CNDP is often described as if it had exactly the same power as a European data-protection authority to impose large GDPR-style administrative fines. The current Moroccan system is different. Law No. 09-08 contains criminal offences and fines, including provisions in Articles 52 to 66, but judicial authorities play a central role in imposing penal sanctions. Article 61 should not be presented as a universal “CNDP fine of 300,000 dirhams” applicable to every breach.
Depending on the offence, fines and imprisonment may apply, and the rules concerning legal persons can increase financial exposure. The exact provision must be matched to the conduct: unlawful sensitive-data processing, failure to respect security obligations, illegal international transfer, obstruction or continued processing despite a lawful order are not interchangeable offences.
In practice, CNDP proceedings can take months, particularly in technically complex files. Resources are not unlimited, and some cases lead to compliance recommendations or corrective measures rather than an immediate public sanction. That does not make a complaint useless. A documented CNDP file can clarify facts, preserve the regulatory dimension of the dispute and support later civil or criminal proceedings.
Prior formalities for health-data processing
Under Article 12 of Law No. 09-08, processing involving sensitive data is generally subject to prior authorisation, subject to statutory exceptions. A clinic launching an application should map every category of information, identify recipients and subcontractors, define retention periods, document security and examine transfers abroad before processing begins.
CNDP deliberations, including published materials associated with health-data processing, provide useful guidance. However, the precise scope and current status of any cited deliberation should be verified directly in the CNDP’s official database rather than relying on a secondary summary.
There is no statutory guarantee that every complex health-platform application will be approved within three to six months. That range may be encountered in practice, but timing depends on the completeness of the file, requests for additional information and the technical architecture. Launching first and seeking approval later is a risky strategy.
For difficult compliance matters, an lawyer specialising in personal-data protection or an digital law lawyer in Morocco can audit the processing operation before it becomes a dispute.
Legal remedies for a patient harmed by digital healthcare
First step: preserve evidence immediately
Digital evidence is fragile. Save the consultation report, electronic prescription, payment receipt, emails, messages, screenshots and the platform’s terms of use. Record the date, time, doctor’s displayed identity and technical incidents. Request access logs and a copy of the medical file quickly, before ordinary retention or deletion processes remove useful traces.
In legal practice, the first reflex of many clients harmed during a teleconsultation is to wait. That is precisely what they should avoid. Connection logs, notification histories and digital traces can disappear quickly: capture everything immediately.
Do not secretly manipulate documents or gain unauthorised access to another person’s account. Evidence should be preserved lawfully. Where the stakes are high, a judicial officer’s report or court-ordered expert measure may give screenshots and digital records stronger evidential value.
Complaint to the Order of Physicians
A patient may complain to the competent regional council of the Order of Physicians where a doctor may have breached professional duties. The complaint should identify the practitioner, describe the facts chronologically and attach copies of supporting documents. The ordinal route is generally accessible without court fees, although legal assistance may help in a complex case.
Do not assume that every regional council must issue a final decision within exactly 60 days. Internal processing, requests for observations and disciplinary procedure can take longer. Moreover, disciplinary proceedings are not a substitute for compensation. The Order may address professional misconduct, but damages are awarded through the competent courts.
Complaint to the CNDP
For unlawful access, disclosure, inadequate security, unexplained advertising use or refusal to honour data rights, submit a complaint through cndp.ma or by a traceable written filing. Attach the original access request, proof of delivery, the controller’s answer, screenshots and any evidence of disclosure.
State precisely what you want: cessation of unlawful processing, identification of recipients, correction, deletion where legally available, preservation of logs, or investigation of an international transfer. A vague allegation that “my privacy was violated” is less effective than a dated, documented account.
Civil, administrative and criminal proceedings
A claim against a private doctor or clinic will ordinarily be brought before the competent court of first instance, subject to the nature and value of the dispute. The mere fact that a platform is a commercial company does not automatically mean that a patient, acting as a non-trader, must sue only before the commercial court. Jurisdiction depends on the parties, the legal character of the dispute and applicable procedural rules.
Where harm is attributed to the operation of a public hospital or public healthcare service, the administrative courts may have jurisdiction under Article 8 of Law No. 41-90, which includes actions for compensation caused by the acts or activities of public-law entities. An medical law lawyer in Rabat may be particularly useful for proceedings involving central public institutions, while patients may also consult a medical law lawyer in Casablanca or a health law lawyer in Marrakech according to territorial jurisdiction.
Criminal proceedings may be considered for breach of medical secrecy, fraudulent access, falsification, fraud or other offences. A complaint may be filed with the Public Prosecutor at the competent court of first instance, but criminal qualification should be assessed carefully. Not every medical error is a crime.
Medical cases often require an expert assessment. The expert may examine whether the consultation met scientific standards, whether an in-person referral was necessary and whether the alleged fault caused the injury. In a digital case, a separate IT expert may be needed to examine logs, authentication, software behaviour and document integrity.
Lawyers’ fees are not fixed by a statutory tariff for this type of litigation. For a substantial digital medical-liability file, market fees may range roughly from 8,000 to 25,000 dirhams, and can be higher for appeals, multiple experts or technically complex proceedings. Expert fees, judicial officer costs, translations and appeal costs may be additional. A written fee agreement is strongly recommended.
Limitation periods: avoid simplified internet formulas
Article 106 of the DOC provides a five-year limitation period for actions arising from an offence or quasi-offence, running from the time the injured person became aware of the damage and the person responsible, subject to the long-stop rule stated by the article. This provision may apply to a delictual claim against a doctor, platform or other private actor.
Article 106 of the DOC: the action for compensation arising from an offence or quasi-offence is time-barred after five years from knowledge of the damage and the responsible person, and in all cases within the maximum period specified by the article from the harmful act.
It is incorrect to say that Article 8 of Law No. 41-90 creates a universal four-year limitation period for claims against public hospitals. Article 8 concerns the jurisdiction of administrative courts, not a general four-year prescription rule. Public-law limitation and forfeiture questions depend on the legal basis of the claim and any applicable public-finance rules.
Likewise, the limitation period for a criminal complaint must be checked under the current Code of Criminal Procedure and the classification of the offence. It should not automatically be stated as five years for every misdemeanour. Amendments, interruption and suspension rules can change the calculation. Consult counsel early rather than waiting for the final months.
What remains unresolved
Medical artificial intelligence
Algorithms can detect suspicious lesions, prioritise radiology images and suggest diagnoses. Moroccan law does not yet offer a sufficiently detailed, health-specific regime for certification, clinical validation, explainability and post-market monitoring of these systems. Who validates an algorithm trained mainly on foreign populations? Who must report a dangerous software update? Can a patient demand human review? These questions require express answers.
Cross-border telemedicine
A Moroccan patient may consult a French, Tunisian or Canadian physician through an international platform. But Law No. 131-13 generally requires legal authorisation and registration conditions for medical practice in Morocco. The location of the patient, practitioner, platform and damage may point to different laws and courts.
This is a major legal risk. Even where the consultation is lawful in the doctor’s country, enforcing a Moroccan judgment abroad, obtaining medical records or proving professional insurance coverage can be difficult. Patients should verify the physician’s registration, the applicable law, the dispute-resolution clause and the insurer covering cross-border care.
Digital exclusion and equal access
Digital healthcare can improve access for remote communities, but it can also create a two-tier system. Rural connectivity, disability, literacy, language and the cost of devices remain practical barriers. HCP and national telecommunications data show continuing differences in internet use between households and territories, even though access has increased substantially.
A digital health law should therefore preserve non-digital routes. No patient should lose access to care, reimbursement or medical records because he or she cannot operate an application. Assisted access points, paper alternatives and accessible interfaces are legal equality issues, not optional customer-service features.
Five rights every Moroccan patient should exercise now
Even before any broader digital health bill is adopted, patients already possess enforceable protections. They should remember five essentials:
- The right to clear medical information and meaningful consent, including an explanation of the limits of remote examination.
- The right to confidentiality, protected by Law No. 09-08, professional ethics and Article 446 of the Criminal Code.
- The right to access and correct personal medical data under Articles 7 and 8 of Law No. 09-08.
- The right to appropriate care, including referral to an in-person examination when telemedicine is insufficient.
- The right to seek a remedy before the Order of Physicians, the CNDP and the competent civil, administrative or criminal court.
Before booking, ask who operates the platform, where data are hosted, how much the consultation costs, whether AMO or private insurance will reimburse it, and how to obtain the report. After the appointment, download the prescription and record while they remain available.
For serious injury, suspected data leakage, unauthorised insurer access or a dispute involving several technology providers, contact a lawyer experienced in medical or digital law. The combination of medical expertise, IT evidence and procedural deadlines makes these files unusually demanding.
Finally, citizens should monitor the General Secretariat of the Government and the Bulletin Officiel, rather than relying solely on announcements concerning a project. Adoption is only the beginning. Decrees, technical standards, budgets and enforcement determine whether statutory rights become real. Morocco’s experience with Law No. 131-13, some of whose implementation mechanisms took years to develop, is a useful warning: vigilance after promulgation matters just as much as debate before it.

