Cookies in Morocco: what deliberation D-939-2025 really requires

Since 28 November 2025, the CNDP regulates cookies through a simplified-declaration model. Which cookies need consent, which are exempt, the maximum retention, and what must not be confused with European doctrine.

  • Cookies
  • D-939-2025
  • CNDP
  • Consent
  • Websites

Cookie banners copied from European websites are everywhere. They are rarely adapted to Moroccan law. Since 28 November 2025, CNDP deliberation no. D-939-2025 sets its own framework — simpler on some points, stricter on others. Here is what it says, section by section.

§1 is unambiguous: the deliberation “applies to any declaration to be made by a controller wishing to process personal data through the installation, recording and/or storage of cookies on the user’s terminal” (our translation). §2 describes the data as “not anonymized”.

Consequence: a site that sets cookies implements a processing operation, with the obligations that go with it.

The permitted purposes (§3)

The simplified declaration only covers four purposes:

  • display of personalized advertising based on the browser or location, “without establishing a personal profile”;
  • personalization of editorial content based on previous choices;
  • sharing of information on social networks;
  • “production of browsing statistics and audience measurement of the website (without establishing the user’s personal profile)”.

And a clear limit: “Any use of the user’s personal data in order to establish their personal profile requires prior authorization from the CNDP under article 12 of Law 09-08.” Profiling therefore falls outside the simplified declaration.

Six months, no more (§5)

“Data collected via cookies must be kept for a maximum of six months. Beyond that, it must be deleted or anonymized.” An analytics cookie configured for two years exceeds this cap by a wide margin. It is one of the most frequent findings in our audits, and one of the simplest to fix.

This is where Moroccan law diverges most from what many people assume. The text says: “For the purposes referred to in paragraph 3 above, the processing of cookies does not require the user’s prior consent, with the exception of cookies used for: personalized advertising; social-network sharing features.”

Interpretation: audience-measurement and editorial-personalization cookies, without a personal profile, are exempt from prior consent. A statistics tool fired before any interaction is therefore not, in itself, a breach of D-939-2025 — it remains subject to the information obligation and the simplified declaration. An advertising pixel or a social-sharing button that sets a cookie before consent, on the other hand, is.

For cookies subject to consent, §6 requires that consent “be expressed by a clear and explicit action, and collected through simple and accessible means”, allowing the user “to refuse the installation”. The refusal is kept for six months at most.

What the text does not say: it does not literally require a “Reject all” button at the same visual level as “Accept”. That requirement comes from French doctrine. Demanding it in the CNDP’s name would be a misattribution — even if, in practice, it is the safest way to satisfy “simple and accessible means”.

Prior information, in every case (§6)

Consent or not, the controller must, “before the first cookie is set”, communicate: its identity, the purposes of the cookies, the categories of data collected, “the recipients of the data, including transfers abroad duly authorized by the CNDP”, the contact details for exercising rights, and “the references of the receipts issued by the CNDP”.

A “Cookie policy” page reachable from the banner fulfils this obligation, provided it is complete.

The simplified declaration (§8)

“Before implementing the processing of personal data through the installation, recording and storage of cookies, controllers must […] file a simplified declaration with the CNDP, via the appropriate forms or the CNDP-FORMS platform.” Sites already operating on the date of the deliberation must bring themselves into compliance and file that declaration.

Transfers and interconnections (§9 and §10)

Cookie data “may not be transferred abroad without the prior authorization of the CNDP”. An audience-analytics tool hosted outside Morocco falls into this case. And any interconnection with other files serving different purposes requires an authorization.

Applicable sanctions

An advertising tracker set without consent is assessed under article 4 of the law (consent) and article 3 (fairness). Articles 54 and 56 provide for three months to one year of imprisonment and a fine of 20,000 to 200,000 MAD, doubled for legal entities (art. 64).

The radical choice

Interpretation: a site that sets no cookies has no banner to display, no simplified declaration to file and no retention period to monitor. This website is the illustration: no cookies, no third-party scripts, a language preference stored locally in the browser and never transmitted. For a showcase site, that is often the best effort-to-compliance ratio.

Articles on regulatory topics are technical and documentary analysis, not legal advice. Excerpts from legal texts are reproduced from official publications; our interpretations are flagged as such.

Got an idea in mind?

Let's discuss how AI can revolutionize your business processes and drive growth.

Contact us