Back to Intelligence Feed
Cybersecurity7 min readRising Group

The Enterprise Guide to CNDP Law 09-08 & DGSSI Security Compliance in Morocco

A complete breakdown of Moroccan data privacy regulations, cross-border data transfer rules under Article 52, and DGSSI infrastructure hardening requirements for companies operating in Casablanca, Rabat, and Tangier.

Understanding Data Protection & Governance in Morocco

As digital transformation accelerates across North Africa, corporate data protection has shifted from an operational luxury to a strict legal necessity. In Morocco, two primary frameworks govern enterprise information security: Loi 09-08 (administered by the CNDP) and security directives enforced by the DGSSI.

Key Pillars of CNDP Law 09-08

Under Moroccan law, any business processing personal data belonging to Moroccan citizens or employees must comply with strict data collection, storage, and processing rules:

  • Article 23 (Data Encryption & In-Transit Security): Requires mandatory 256-bit SSL/TLS encryption for all web applications.
  • Article 52 (Cross-Border Data Transfer Restrictions): Prohibits transferring personal data outside Moroccan territory without prior explicit CNDP authorization.

DGSSI Directives for Critical Infrastructure

For financial institutions, telecom operators, and government contractors, DGSSI security guidelines mandate regular Offensive Penetration Testing, zero-trust network segmentation, and automated log auditing.

The Enterprise Guide to CNDP Law 09-08 & DGSSI Security Compliance in Morocco — Rising Atom