Law 09-08: what your website must display, and what it must not collect
A Moroccan website with a contact form is already a “processing of personal data”. Here, article by article, is what Law 09-08 requires before the very first submission.
Many Moroccan companies assume personal-data protection is a matter for banks, clinics or telecom operators. In reality, Law 09-08 applies as soon as a website has a form asking for a name and an email address. This article spells out what that means in practice.
A contact form is a processing operation
The law defines personal data very broadly. Article 1 speaks of “any information, of whatever nature and regardless of its medium, including sound and image, concerning an identified or identifiable natural person” (our translation). A name, a nominative email address, a phone number: all of these fall within the definition.
The same article defines processing as “any operation or set of operations, whether or not performed by automated means, applied to personal data, such as collection, recording, organization, storage […]”. Receiving a form submission and storing it in a database is collecting and storing. The website is therefore a data controller within the meaning of the law.
Before the first collection: the declaration (art. 12)
Article 12 sets the principle: except where specific legislation provides otherwise, the processing of personal data must be the subject of a prior declaration — or of a prior authorization in sensitive cases (health data, opinions, national ID number, etc.).
That declaration is filed with the CNDP, today via form F211 or the CNDP-FORMS platform. According to article 15 it must contain the controller’s name and address, the purposes, the categories of data, the recipients, the intended transfers abroad, the retention period, the department where rights are exercised and a description of security measures.
The CNDP then issues a receipt. Article 19 sets the deadline and the resulting obligation: the Commission issues, within 24 hours of the filing, a receipt “whose characteristics must appear in all data collection or transmission operations”.
In other words: the receipt number must be shown under every form.
Under the form: the information notice (art. 5)
Article 5 requires informing the person “expressly, precisely and unequivocally” before collection. The mandatory items are:
- the identity of the data controller;
- the purposes of the processing;
- the recipients or categories of recipients;
- whether answers are mandatory or optional;
- the existence of rights of access and rectification;
- “the characteristics of the receipt of the declaration with the National Commission”.
The CNDP publishes on its portal a standard notice that contains exactly these items. It begins (our translation): “Through this form, (name of the controller) collects your personal data for the purpose of (state the purpose). This processing was declared to / authorized by the CNDP under number (receipt number).”
The implementing decree adds a requirement that is often forgotten. Article 43 of Decree 2-09-165 provides that where data is collected in writing, the controller asks the person, “on the document used to collect the data, whether they wish to exercise the right of opposition”. On a web form, that translates into an opposition checkbox, presented before validation.
What the site must not collect
Article 3 sets the proportionality principle: data must be “adequate, relevant and not excessive in relation to the purposes for which it is collected”. A contact form asking for a date of birth, a national ID number or a full postal address goes beyond what is needed to answer a question.
The national ID number even falls under prior authorization (art. 12, 1-e), not mere declaration. Collecting it “just in case” is an expensive mistake.
What a non-compliant site risks
The sanctions chapter is precise. Article 52 punishes “with a fine of 10,000 to 100,000 MAD anyone who implements a personal data file without the declaration or authorization required by article 12”. Article 54 targets unfair collection or diversion of purpose, with imprisonment of three months to one year and a fine of 20,000 to 200,000 MAD.
And article 64 specifies that when the offender is a legal entity, “the fines are doubled”.
Our reading
Interpretation, not the text of the law: for a showcase site, the simplest path is often to collect nothing at all. A displayed email address, without a form, is not a processing operation implemented by the site. If a form is essential, the order is: file the declaration, obtain the receipt, display the standard notice with the number, add the opposition checkbox, and check where the submission goes — a server abroad opens a second topic, articles 43 and 44, which we cover in the next article.
Quick checklist
- Does the form really exist for a precise purpose?
- Is the processing declared (F211) and the receipt obtained?
- Is the information notice displayed under the form, with the receipt number?
- Is an opposition checkbox present before validation?
- Are the fields limited to what is strictly necessary?
- Where are submissions stored, and by whom?
Articles on regulatory topics are technical and documentary analysis, not legal advice. Excerpts from legal texts are reproduced from official publications; our interpretations are flagged as such.
Related reading
Cookies in Morocco: what deliberation D-939-2025 really requires
Since 28 November 2025, the CNDP regulates cookies through a simplified-declaration model. Which cookies need consent, which are exempt, the maximum retention, and what must not be confused with European doctrine.
Read the article →Hosting abroad is transferring: reading articles 43 and 44 of Law 09-08
A host in France, an emailing tool in the United States, an AI API in the cloud: every flow leaving Morocco is a transfer subject to a precise regime. What the law, the decree and the adequacy list actually say.
Read the article →