Business Law14 min read

Personal Data Protection in Morocco: What Companies Must Do Before the CNDP

By Karim Bensouda

Legal Editor — Employment Law

Published on
Personal Data Protection in Morocco: What Companies Must Do Before the CNDP

Personal data protection in Morocco is now a business-critical issue

A Casablanca SME owner recently discovered, during due diligence requested by a banking partner, that his company had been processing personal data for nearly five years without completing a single formality before the Commission Nationale de contrôle de la protection des Données à caractère Personnel, better known as the CNDP. The business maintained a customer database, employee files, CCTV recordings, email marketing lists and a cloud-hosted CRM. None had been properly mapped. Several required a declaration, while others raised questions of prior authorisation and international data transfers.

This situation is far from exceptional. Morocco has had a personal data protection statute since 2009, yet a considerable gap remains between the number of processing operations actually carried out by businesses and those formally brought into compliance. Many managers still believe that the law concerns only banks, telecom operators or large digital platforms. It does not.

The alliance between the APEBI and the APDND, reported by Medias24 as an initiative intended to reinforce digital trust, is therefore more than a sectoral announcement. It signals that data governance is becoming part of Morocco's economic competitiveness. Companies supplying European clients, operating call centres, exporting digital services or using foreign cloud platforms are already being asked to demonstrate their compliance.

In practical terms, personal data protection is no longer a file to leave with the IT department. It affects contracts, human resources, marketing, cybersecurity, procurement and corporate reputation. Non-compliance may result in criminal exposure, intervention by the CNDP, disruption of a business process or the loss of a major customer.

From Law 09-08 to the APEBI-APDND digital trust initiative

The legal framework is not new. It rests principally on Law No. 09-08 on the protection of individuals with regard to the processing of personal data, promulgated by Dahir No. 1-09-15 of 22 February 2009 and published in Official Bulletin No. 5714 of 5 March 2009. Its implementing framework includes Decree No. 2-09-165 of 21 May 2009, published in Official Bulletin No. 5744 of 18 June 2009.

What is changing is the market. Moroccan firms are processing more information, using more software-as-a-service tools and exchanging more data across borders. At the same time, clients and investors are conducting stricter compliance audits. The APEBI-APDND initiative fits into this movement towards stronger digital confidence and closer alignment with international practices.

Law 09-08: the foundation of data protection in Morocco

Which companies and processing operations are covered?

Article 1 of Law 09-08 defines personal data broadly. It covers any information, regardless of its form or medium, relating to an identified or identifiable natural person. Identification may be direct, through a name or national identity number, or indirect, through a telephone number, location, customer identifier, photograph, IP address or combination of characteristics.

Article 1, in practical terms: if information can be connected to a particular employee, customer, prospect, patient, supplier or website user, it should be treated as personal data. A company does not escape the law merely because its database contains customer numbers instead of names.

The word processing is equally broad. It includes collection, recording, organisation, storage, alteration, consultation, disclosure, transmission, matching, blocking and deletion. A spreadsheet containing customer telephone numbers is a processing operation. So is a paper archive organised by employee name, a biometric attendance terminal, a CCTV system or a mailing platform.

Article 2 determines the territorial and material scope of the statute. Subject to its statutory exceptions, the law applies to automated processing and to non-automated information intended to form part of a structured filing system. Processing carried out exclusively for personal or household activities falls outside the ordinary regime. Certain state activities connected with national defence, internal or external security and crime prevention are governed by special provisions rather than ordinary commercial rules.

For businesses, the sectors most exposed are human resources, healthcare, finance, insurance, e-commerce, direct marketing, hospitality, education, outsourcing and call-centre operations. Yet even a small restaurant may process reservation details, employee information and CCTV images. Size does not create a general exemption.

The principles every controller must respect

Article 3 of Law 09-08 establishes the core data-quality principles. Personal data must be processed fairly and lawfully, collected for specific, explicit and legitimate purposes, remain adequate and proportionate, be accurate and be retained only for the period required by the stated purpose.

Concretely, an employer collecting a worker's bank details for salary payment cannot reuse them for an unrelated commercial campaign. An online shop should not retain abandoned customer accounts indefinitely merely because storage is inexpensive. A clinic cannot allow unrestricted access to patient files simply because its software technically permits it.

Article 4 addresses the legitimacy of processing. Consent is one possible basis, but not the only one. Processing may also be justified where necessary for a contract, compliance with a legal obligation, protection of vital interests, performance of a public-interest task or pursuit of a legitimate interest that does not override the person's fundamental rights.

This matters because Moroccan companies too often request consent for everything. An employer does not normally need an employee's consent to transmit salary information to the CNSS where the transmission is legally required. Conversely, adding that employee to an unrelated advertising database cannot automatically be justified by the employment contract.

Sensitive data and high-risk identifiers

Article 5 gives enhanced protection to sensitive data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, or information concerning health and genetic characteristics. Processing such data is generally prohibited unless a statutory exception applies and the required CNDP formality has been completed.

Other provisions apply to criminal information, the national identity number and interconnections between files serving different purposes. These operations should not be confused with ordinary customer management. Medical practices should seek advice from lawyers specialising in Moroccan health law before deploying shared patient-management platforms or outsourcing medical archives.

The CNDP: mandate, composition and actual powers

An authority created by Law 09-08

Article 27 of Law 09-08 established the CNDP. The Commission is responsible for ensuring that personal data processing respects fundamental rights, privacy and the statutory requirements. Its members are appointed under the institutional arrangements set out by the law, and the Commission has deliberative, advisory and supervisory functions.

The CNDP receives declarations and applications for authorisation, examines international transfer requests, handles complaints, issues opinions and deliberations, and conducts awareness work. It may also verify compliance on documents and on company premises through duly authorised officers, subject to the procedural safeguards provided by law.

In practice, a CNDP inspection may involve reviewing declaration receipts, privacy notices, employment forms, access-control systems, processor contracts, security measures and the actual operation of databases. A beautifully drafted policy will not be enough if reception staff share passwords or former employees retain access to the CRM.

CNDP enforcement and the limits of the Moroccan framework

The CNDP may issue observations, request corrective action and refer suspected criminal offences to the competent public prosecutor. Depending on the legal basis and seriousness of the matter, the processing may also face suspension, withdrawal of an authorisation or judicial consequences.

Historically, the regulator has often favoured education and remediation. That approach helped organisations understand a relatively new field, but it also encouraged some businesses to regard CNDP compliance as optional. This calculation is becoming less defensible. Procurement teams, banks and international customers increasingly demand proof before regulators need to intervene.

Comparisons with the EU General Data Protection Regulation must remain precise. Law 09-08 shares principles with European data protection law, but it is not a Moroccan copy of the GDPR. It does not reproduce the GDPR's entire accountability architecture, administrative fine model, 72-hour breach notification rule or mandatory data protection officer regime. A company can therefore comply with one framework and still have outstanding obligations under the other.

CNDP declaration or prior authorisation: which procedure applies?

The ordinary declaration

The system of prior formalities appears principally in Articles 16 to 24 of Law 09-08. Under Article 16, wholly or partly automated processing must generally be declared to the CNDP before implementation unless it falls under an exemption, a simplified standard or the prior-authorisation regime.

An ordinary declaration will commonly cover customer administration, invoicing, supplier management, standard human resources administration or a non-sensitive prospect database. Calling it an ordinary declaration does not mean that the controller may ignore information, security, retention and individual-rights requirements.

Article 17 identifies information to be provided in the declaration, including the controller, purposes, categories of persons and data, recipients, retention arrangements, security measures and contemplated foreign transfers. Under Article 18, the CNDP issues a receipt for a complete declaration. This receipt is not a certificate that every operational detail is lawful; the controller remains responsible for compliance.

When prior authorisation is required

Article 20 places specified higher-risk processing operations under prior authorisation, notably processing connected with sensitive categories and other situations identified by the law. Provisions concerning criminal data, national identity numbers and file interconnections must also be examined. Biometrics, including fingerprint attendance systems, have been addressed through CNDP deliberations and should never be installed as if they were ordinary time sheets.

A Moroccan company using fingerprints to monitor attendance should assess necessity and proportionality. Could an individual badge achieve the same purpose with less intrusion? If so, a biometric system may be difficult to justify. The company must also consider employees who cannot or should not provide the relevant biometric characteristic.

Under Article 23, the Commission decides on an authorisation application within the statutory period of two months, which may be extended once for an equivalent period by reasoned decision. In real files, missing contracts, vague retention periods or unclear hosting arrangements can generate exchanges that extend the overall timetable. Two to four months is therefore a sensible planning assumption, not a guaranteed result.

How to file with the CNDP

Current forms, filing channels and supporting-document requirements should be checked on the official CNDP website. The substance of a sound application generally requires the following work:

  1. Identify each processing purpose rather than declaring the company in one vague file.
  2. List the exact data categories, persons concerned, internal users and external recipients.
  3. Fix and justify retention periods.
  4. Describe authentication, access, backup, logging and deletion measures.
  5. Attach relevant notices, consent language, contracts and transfer documentation.
  6. Submit the correct declaration, authorisation and foreign-transfer forms.

CNDP procedures themselves are not ordinarily treated as a commercial licence carrying a filing fee. Professional support, however, has a cost. A straightforward declaration may generate legal fees of approximately MAD 3,000 to MAD 8,000; a multi-processing compliance project or complex cloud-transfer file will cost more. These are market estimates, not regulated tariffs. Businesses in Rabat may consult business-law counsel familiar with CNDP procedures.

Article 24 must also be kept in mind: substantial changes to a processing operation may require an updated formality. Changing from local hosting to an American cloud provider, adding biometrics or extending a customer file to behavioural profiling is not a harmless technical modification.

Operational duties of a Moroccan data controller

Who is the controller?

Under Article 1, the controller is the natural or legal person that determines the purposes and means of processing. For a limited liability company, the controller will ordinarily be the company itself, represented by its manager, rather than the IT technician who installed the software. Senior management nevertheless carries corporate and, depending on the offence, potential personal exposure.

A processor, by contrast, handles data on behalf of the controller. Payroll firms, hosting companies, call centres, software providers and document-archiving businesses may occupy that role. Labels do not decide the issue: a provider that independently determines how data will be exploited may become a controller for that activity.

Information duties

Articles 9 and 10 govern information to be supplied when data is collected from the person or obtained through another source. Notices should identify the controller, explain the purposes, state whether replies are compulsory, identify recipients and explain the rights of access, rectification and opposition.

In plain English, a website form should not merely say “we respect your privacy.” It should tell the user who is collecting the information, what will be done with it, who will receive it, whether it will leave Morocco, how long it will be retained and how statutory rights may be exercised.

Copying a French GDPR notice is a frequent mistake. Such a notice may identify a European supervisory authority, invoke legal bases without considering Moroccan law and omit the CNDP formality. A Moroccan privacy policy should reflect the actual processing and the applicable jurisdictions.

Security and processors

Article 23 is sometimes incorrectly cited online as the general security provision. In fact, the core confidentiality and security duties appear in Articles 14 and 15. The controller must adopt appropriate technical and organisational precautions, having regard to the nature of the data and the risks. A processor must offer sufficient safeguards and act within the contractual and operational limits imposed by the controller.

Practical meaning: access must be limited by role; former staff accounts must be disabled; backups must be protected; sensitive files should be encrypted where appropriate; incidents should be logged; and processors should sign enforceable data-protection and confidentiality clauses.

A Casablanca medical practice once used a shared management platform administered by an unrelated service company. Technicians could access patient notes through a universal administrator password, and the service contract said nothing about confidentiality, deletion or incident handling. The problem was not merely technical. It directly concerned the controller's duties under Articles 14 and 15.

Rights of customers, employees and other individuals

Access, rectification and opposition

Article 11 establishes the right of access. A person may ask the controller to confirm whether data concerning them is being processed and to communicate intelligible information about that processing. The statutory response period under Law 09-08 is generally ten clear days, not the one-month GDPR period often copied into Moroccan procedures.

Article 12 provides for rectification, updating, blocking or deletion where data is inaccurate, incomplete, ambiguous, outdated or unlawfully processed. Article 13 establishes a right to object on legitimate grounds and, in particular, supports opposition to direct marketing.

These rights also apply in employment. A worker may request access to personal information contained in HR, appraisal or attendance systems, subject to the rights of others and legally protected information. Employers using biometrics, CCTV or monitoring tools should obtain employment-law advice from Moroccan labour lawyers, because data protection and workplace rules overlap.

A practical request-handling procedure

Every company should create a dedicated address, such as privacy@company.ma, and record the date, identity verification, scope, responsible team and final response for each request. Identity checks must be proportionate: sending a full national identity card by unencrypted email should not become the default for a minor newsletter objection.

The controller should search all relevant systems, including archived email, outsourced payroll tools and CRM notes. It should also avoid disclosing another person's information. A response log is valuable evidence if the requester later complains to the CNDP.

International transfers and foreign cloud services

The rule under Article 43

Article 43 of Law 09-08 provides that personal data may be transferred to a foreign state only where that state offers a sufficient level of protection, assessed by reference to its law, security measures, data characteristics, purpose and duration of processing. The CNDP's current position and published transfer materials should be checked for each destination and operation.

Transfers are not limited to emailing a database abroad. Remote access by an overseas support team, hosting in a foreign data centre, synchronisation with a global CRM and backup to an offshore server may all constitute transfers.

Articles 44 and following provide mechanisms and exceptions for particular circumstances, including specified consent, contractual necessity, public interest, legal claims, vital interests and transfers from certain public registers. These exceptions must be interpreted carefully. A generic clause hidden in employment terms does not automatically legalise continuous cloud hosting abroad.

Google, Microsoft, Salesforce and other SaaS platforms

Use of an American cloud provider is not automatically illegal, but it is not automatically compliant either. The company must identify hosting and support locations, subprocessors, contractual safeguards and the relevant CNDP transfer formality. Contractual clauses are useful, but a private contract does not by itself replace an authorisation required under Moroccan law.

A Moroccan export company reportedly lost momentum in negotiations with a French principal because it could not explain where its sales-team data was hosted or produce CNDP transfer documentation. The French buyer viewed the absence of governance as a supply-chain risk. That commercial consequence arrived before any fine.

Businesses deploying foreign cloud tools should consult Moroccan data and cybersecurity counsel. A realistic transfer-authorisation project may take two to four months where provider documentation, data-centre locations and subprocessor lists must first be clarified.

Morocco and EU adequacy are not the same question

Morocco does not currently benefit from a European Commission adequacy decision under Article 45 of the GDPR. Consequently, an EU company transferring personal data to a Moroccan service provider will ordinarily need an appropriate GDPR transfer mechanism, such as the European Commission's standard contractual clauses, together with the required transfer-risk assessment.

The reverse flow must be assessed under Law 09-08 and the CNDP's rules. One should not simply assume that European GDPR status automatically resolves every Moroccan formality. This distinction is vital for call centres, software developers and business-process outsourcing providers.

Penalties and business risks

Criminal sanctions under Law 09-08

The criminal provisions appear in Articles 51 to 65. Contrary to figures sometimes circulated online, the offence of implementing processing without the required declaration or authorisation is addressed by Article 52, which provides for imprisonment of three months to one year and a fine of MAD 20,000 to MAD 200,000, or either penalty alone.

Article 51 penalises unjustified refusal to respect rights of access, rectification or opposition with a fine of MAD 10,000 to MAD 100,000. Other provisions punish unlawful collection, misuse of data, prohibited sensitive-data processing, excessive retention, unlawful disclosure, obstruction and transfers made in breach of the statutory rules. The exact charge depends on the conduct; one should not collapse the entire sanctions chapter into a single “CNDP fine.”

Article 64 provides for increased penalties in the event of recidivism, while Article 65 addresses the liability of legal persons and permits fines applicable to them to be doubled, without excluding sanctions against natural persons responsible for the offence. These distinctions matter when assessing the exposure of a company and its managers.

Commercial damage may be greater than the fine

A processing operation may need to be stopped or redesigned. A customer may terminate a contract. A tender may be lost because the bidder cannot produce CNDP receipts or transfer approvals. Following a breach, screenshots and allegations can circulate on social media long before the legal facts are established.

Law 09-08 does not reproduce the GDPR's general 72-hour personal-data-breach notification rule in identical terms. Nevertheless, a breach may reveal a violation of Articles 14 and 15, trigger contractual notification clauses and require urgent engagement with the CNDP or other authorities. Companies should maintain an incident plan rather than wait for a statutory debate while compromised data circulates.

A practical Law 09-08 compliance plan for Moroccan SMEs

Step 1: map every processing operation

Begin with reality, not templates. Interview HR, sales, accounting, IT, marketing and security teams. Record the purpose, data categories, individuals, legal basis, recipients, hosting location, retention period, security measures and CNDP formality for each operation.

A spreadsheet is enough for a first audit. Typical entries include recruitment, payroll, CNSS reporting, access control, CCTV, customer support, invoicing, prospecting, website analytics, cookies, newsletters, supplier contacts and litigation files.

Step 2: classify the required formalities

Separate ordinary declarations from processing requiring prior authorisation. Then identify every foreign transfer. Do not bundle unrelated purposes merely to reduce paperwork. Employee administration, biometrics, CCTV and customer marketing may require distinct analyses.

Step 3: repair documentation and contracts

Draft or update privacy notices, forms, website policies, processor agreements, confidentiality clauses, retention schedules, access-request procedures and incident protocols. An e-commerce operator should also align its privacy wording with its terms of sale and consumer-facing checkout process. Specialist support is available from Moroccan e-commerce lawyers.

Step 4: strengthen actual security

Legal documentation cannot compensate for shared accounts and uncontrolled exports. Introduce role-based access, multifactor authentication where justified, secure backups, patch management, encryption, logging and formal account closure. Test restoration and incident procedures. Ask providers for evidence rather than accepting the phrase “GDPR compliant.”

Step 5: appoint a data protection contact

Law 09-08 does not impose a GDPR-style data protection officer in the same general terms. Even so, appointing a trained privacy contact is sensible. This person can coordinate CNDP filings, individual requests, contract reviews, incidents and annual audits.

For an SME, an external part-time adviser may cost approximately MAD 1,500 to MAD 5,000 per month, depending on data volume and risk. A broader initial compliance project for a company with 10 to 50 employees may range from MAD 15,000 to MAD 40,000. These indicative market ranges vary significantly; quotations should define deliverables.

Budget and timetable

A relatively straightforward SME may complete its first compliance cycle in three to six months. Businesses handling health data, biometrics, extensive CCTV or multiple international platforms should allow more time. Lawyers specialising in digital law in Casablanca or business law in Marrakech can coordinate the legal work with cybersecurity and IT teams.

Compliance is continuous. Review the data map annually and before launching a new application, campaign or monitoring tool. Procurement should not sign a cloud contract before confirming data locations and transfer mechanisms.

How to complain to the CNDP

Preparing a documented complaint

A person who believes that their rights have been infringed may contact the controller and, where the issue is not resolved, submit a complaint to the CNDP. Although prior contact helps define the dispute and prove that the company failed to respond, complainants should verify the CNDP's current form and admissibility instructions rather than assume that every case has the same mandatory 30-day pre-complaint period.

The file should include identification details, the name of the organisation, a precise description of the processing, copies of requests and responses, proof of transmission, screenshots and relevant contracts or notices. Unnecessary third-party data should be removed.

The official complaint form and current submission channels are available at cndp.ma. A dated filing receipt should be retained. The Commission may request explanations from the controller, conduct checks, seek corrective action or refer facts potentially constituting an offence to the public prosecutor.

Judicial remedies remain available

A CNDP complaint does not necessarily exclude civil or criminal proceedings. Depending on the harm and legal basis, the individual may approach the competent court of first instance, while criminal allegations may be reported to the public prosecutor. Appeals then follow the ordinary Moroccan judicial structure, including the courts of appeal and, on questions of law, the Court of Cassation.

Employees should also consider labour-law remedies where misuse of personal data is connected with disciplinary action, dismissal or workplace surveillance. The correct forum depends on the claim; legal advice is recommended before filing parallel proceedings.

CNDP compliance is an investment in trust

The central message is simple. A CNDP declaration for a Moroccan company is not a decorative administrative receipt. Compliance requires lawful purposes, proportionate collection, transparent notices, enforceable processor contracts, security controls, respect for individual rights and proper authorisation of high-risk processing and international transfers.

The APEBI-APDND initiative is a useful warning of where the market is moving. Moroccan businesses will face stronger demands for digital trust, particularly when dealing with banks, public bodies and European clients. The absence of an EU adequacy decision makes demonstrable governance even more valuable for Moroccan technology exporters.

Acting now is usually cheaper than responding during a breach, tender or acquisition. Start with a data map, prioritise HR, customer, CCTV and cloud processing, then file the necessary CNDP formalities. Personal data protection is not merely an IT issue. It is part of the trust between a company, its employees, its customers and its partners.

Frequently Asked Questions

Must my company declare its processing to the CNDP if it collects only employee data?
Yes, employee administration is personal data processing under Law 09-08, and no general exemption exists merely because the individuals are your own employees. Payroll files, recruitment records, appraisals and attendance data will commonly require an ordinary CNDP declaration, subject to the applicable exemption or simplified-standard rules. Biometrics, health information and certain national identity number uses require a more demanding analysis and may fall under prior authorisation. If the HR platform is hosted abroad or accessible by a foreign support team, the company must also assess the international transfer provisions of Article 43 and following.
What is the difference between a CNDP declaration and prior authorisation?
An ordinary declaration under Articles 16 to 18 is generally used for routine processing that does not fall into a higher-risk statutory category. Prior authorisation, governed principally by Articles 20 to 23, applies to specified processing operations involving sensitive data or other risks identified by Law 09-08. The authorisation procedure requires the CNDP to examine the operation before it begins, and Article 23 provides a two-month decision period that may be extended once. Misclassifying an authorisation file as an ordinary declaration can leave the processing unlawfully implemented.
What must a Moroccan e-commerce website do with customer data?
The operator should identify and complete the CNDP formalities applicable to account management, orders, payment, customer support, newsletters, cookies and analytics. Customers must receive clear information under Articles 9 and 10 concerning the controller, purposes, recipients and their rights. Marketing consent should be separate and unambiguous; a pre-ticked box is poor evidence of free and informed choice, while Article 13 protects opposition to direct marketing. Foreign payment, analytics, hosting and CRM providers must also be reviewed under Article 43 and following, with advice from Moroccan e-commerce counsel where needed.
What penalties apply if a company has not declared its databases?
Article 52 of Law 09-08 punishes implementation of processing without the required declaration or authorisation by three months to one year of imprisonment and a fine of MAD 20,000 to MAD 200,000, or either penalty alone. Article 51 separately penalises unjustified refusal to respect access, rectification and opposition rights with a fine of MAD 10,000 to MAD 100,000. Other offences cover unlawful collection, sensitive data, disclosure, retention, obstruction and illegal foreign transfers. Recidivism and liability of legal persons are addressed by Articles 64 and 65, including the possibility of doubled fines for legal entities.
Can a Moroccan company legally use Google, Microsoft or Salesforce?
Yes, potentially, but not without examining the actual data flows. Hosting abroad, overseas support access and global backups may constitute transfers under Article 43, so the destination, contractual safeguards and CNDP formality must be checked. A provider's statement that it is GDPR compliant does not replace Moroccan legal requirements or a required CNDP authorisation. The company should document data-centre locations, subprocessors, security measures, deletion terms and transfer mechanisms before deployment.
Is Morocco recognised by the European Union as providing adequate data protection?
No. Morocco does not currently benefit from an adequacy decision adopted by the European Commission under Article 45 of the GDPR. An EU organisation transferring personal data to Morocco will therefore ordinarily need an appropriate mechanism, such as the European Commission's standard contractual clauses, together with the required transfer-risk assessment. Transfers from Morocco must separately comply with Law 09-08 and the CNDP's rules; the two directions should not be confused.
Must a Moroccan company appoint a Data Protection Officer?
Law 09-08 does not impose a GDPR-style Data Protection Officer requirement in the same general terms as Articles 37 to 39 of the GDPR. Nevertheless, appointing a privacy contact is strongly recommended for organisations handling substantial volumes, sensitive data, biometrics or multiple cloud systems. The contact may be a trained employee or an external lawyer or consultant, provided conflicts of interest and confidentiality are managed. For a small or medium-sized company, external support may cost approximately MAD 1,500 to MAD 5,000 per month, depending on scope.
How can an individual file a complaint with the CNDP?
The person should first document the problem and normally contact the controller so that the request and any failure to respond can be proved. The CNDP's current complaint form and submission instructions are available on its official website, cndp.ma. The file should include identification information, copies of the original request, proof of transmission, the response received and any relevant screenshots or documents. A complaint to the CNDP does not necessarily prevent the person from pursuing an appropriate civil, criminal or employment claim before the competent Moroccan court.

Recommended lawyers

Speak with a lawyer specialized on these topics

Maitre HANANA ABDERRAHIM

Maitre HANANA ABDERRAHIM

Cabinet Me. Maitre HANANA ABDERRAHIMRabat
Droit bancaire & financierReal Estate LawTax Law+15
French · Arabic
Direct contact only
Sofia Bousselham
9 years of experience

Sofia Bousselham

Laya Law FirmCasablanca

Avocate au barreau de Casablanca, Sofia Bousselham accompagne depuis plus de neuf ans entreprises et particuliers dans la sécurisation de leurs activités et la résolution de leurs litiges. Trilingue (français, arabe, anglais), elle intervient tant en conseil qu’en contentieux. Sa pratique se concentre sur le droit social, le droit des sociétés, le droit commercial, la propriété intellectuelle et la protection des données personnelles. À l'écoute et pragmatique, elle privilégie une approche personnalisée et stratégique, alliant rigueur juridique et compréhension des enjeux business de ses clients.

Labor LawBusiness LawIntellectual Property+13
French · Arabic · English
Direct contact only