Hosting abroad is transferring: reading articles 43 and 44 of Law 09-08
A host in France, an emailing tool in the United States, an AI API in the cloud: every flow leaving Morocco is a transfer subject to a precise regime. What the law, the decree and the adequacy list actually say.
The question comes up in almost every audit we do: “our site is hosted with a European provider, is that a problem?” The answer sits in two articles of Law 09-08 and four articles of its implementing decree. Here they are, with what they imply.
The principle: a sufficient level of protection (art. 43)
Article 43 provides (our translation): “The controller of a processing operation may only transfer personal data to a foreign State if that State ensures a sufficient level of protection of the privacy and fundamental rights and freedoms of individuals with regard to the processing to which the data is or may be subjected.”
The same article entrusts the CNDP with drawing up “the list of States meeting the criteria”. That list exists: it is deliberation no. 236-2015 of 18 December 2015, which names thirty-two States. It includes France, Germany, Spain, the United Kingdom, Switzerland, Canada and most of the European Economic Area.
It does not include the United States, the UAE, Turkey, China or India. Interpretation: the list is exhaustive; a State not on it falls under the derogation regime of article 44.
Even to an adequate country, you must notify
This is the most frequently overlooked point. Article 1 of deliberation 236-2015 opens with “Subject to notifying the CNDP, under the appropriate regime, of any transfer of personal data abroad”. And article 46 of Decree 2-09-165 details the content of a transfer request “to a foreign country offering a sufficient level of protection”: name and address of the sender and of the recipient, description of the file, categories of data, data subjects and their approximate number, purpose of the processing at the recipient, mode and frequency of transfers, date of the first transfer.
In other words, hosting with a French provider is still a transfer to be brought to the CNDP’s attention — today via form F118. Article 49 of the decree adds that any change to this information “must be notified to the CNDP within 8 working days”.
Off the list: the derogations of article 44
For a State not on the list, article 44 provides three routes:
- the express consent of the person, or a specific necessity (protection of life, performance of a contract with the person, defence of a legal claim, judicial cooperation, medical prevention or diagnosis…);
- a bilateral or multilateral agreement to which Morocco is a party;
- “the express and reasoned authorization of the National Commission where the processing guarantees a sufficient level of protection […] in particular by virtue of the contractual clauses or internal rules to which it is subject.”
Article 48 of the decree specifies that the applicant then indicates “the measures or arrangements intended to guarantee a sufficient level of protection”. Article 28 of the same decree sets the timeline: the CNDP decides within two months, extendable once; after that, “the authorization is deemed granted”.
What counts as a transfer, concretely
A transfer is not only a database that moves. All of the following are concerned as soon as personal data passes through them:
- hosting of the website and its database;
- a SaaS emailing tool or CRM;
- an audience-analytics service;
- an artificial-intelligence API called with the content of a customer message;
- a backup at a cloud provider.
The CNDP’s recent deliberations repeat it systematically. D-940-2025 on newsletters (§11) and D-939-2025 on cookies (§9) both provide that “the data collected by the controller may not be transferred abroad without the prior authorization of the CNDP”.
The sanction
Article 60 punishes “with imprisonment of three months to one year and a fine of 20,000 to 200,000 MAD, or one of these two penalties only, anyone who transfers personal data to a foreign State in breach of articles 43 and 44”. For a company, article 64 doubles the fine: 40,000 to 400,000 MAD, with possible confiscation and closure of premises.
A note on method
A web server located abroad does not, by itself, prove a transfer of personal data. A static site with no form transmits none. And behind a CDN, the real origin is not observable from outside. In our audit reports this finding is therefore always worded conditionally: “if personal data is stored on or passes through this server, and if no transfer request has been filed…”. That is a matter of honesty, and it is also what makes the report usable.
The choice that removes the question
Interpretation: the simplest way not to have to manage the articles 43-44 regime is not to transfer. Hosting in Morocco — the national operators, several Moroccan hosts, or a cloud region located in Morocco — and AI models deployed on site bring the topic back to the ordinary obligations: declaration, information, security. That is exactly what we offer with local AI deployment.
Articles on regulatory topics are technical and documentary analysis, not legal advice. Excerpts from legal texts are reproduced from official publications; our interpretations are flagged as such.
Related reading
Cookies in Morocco: what deliberation D-939-2025 really requires
Since 28 November 2025, the CNDP regulates cookies through a simplified-declaration model. Which cookies need consent, which are exempt, the maximum retention, and what must not be confused with European doctrine.
Read the article →Law 09-08: what your website must display, and what it must not collect
A Moroccan website with a contact form is already a “processing of personal data”. Here, article by article, is what Law 09-08 requires before the very first submission.
Read the article →