Law 09-08 and customer data in Morocco: merchant guide

Updated 2026-08-25

In Morocco, the protection of personal data is governed by Law No. 09-08. For a merchant setting up a loyalty program, this means one simple thing: collecting a name, telephone number or purchase history is data processing, with obligations to be aware of from the start.

This guide presents the general principles, without jargon, and what DimaCard provides to help you. General information — this is not legal advice.

What Law 09-08 regulates

Treatment is broader than you think

Law 09-08 applies to all processing of personal data: collect, record, organize, store, transmit. A loyalty program checks many of these boxes — even if only by recording a customer's name and visit history. The merchant who launches a loyalty card is therefore directly concerned.

The CNDP, supervisory authority

The National Commission for the Control of Personal Data Protection (CNDP) is the authority responsible for ensuring compliance with Law 09-08. She is the one who receives the preliminary formalities and can control the treatments.

General principles to remember

  • Purpose: each processing must have a specific, explicit and legitimate purpose – in this case, to manage points and rewards.
  • Proportionality / minimization: only collect data that is adequate, relevant and not excessive in relation to the purpose.
  • Consent: for prospecting (offers, reminders, marketing notifications), the consent of the person is the expected basis.
  • Information: the person must be informed of the identity of the data controller, the purpose and their rights.
  • Rights of individuals: right of access, rectification and opposition, under the conditions provided for by law.
  • Security and confidentiality: protect data against unauthorized access, loss or alteration.

Declaration and preliminary formalities

Law 09-08 provides for formalities with the CNDP for certain processing operations — declaration, or even prior authorization depending on the nature and sensitivity of the processing. The exact scope of these formalities depends on the processing concerned: it is better to check the specific case of a loyalty program with the CNDP or a council than to assume it is compliant. The sector's reference sources (CMS Francis Lefebvre, Chambers) remain the right entry point.

The Moroccan trader’s checklist

  • Write the purpose of your program in one sentence, and stick to it.
  • Obtain consent before any marketing prospecting (offers, reminders).
  • Inform your customers: who processes their data, why, and what their rights are.
  • Collect the minimum: a first name and a telephone number are often enough, there is no need to ask for more.
  • Secure access: do not leave the customer file accessible to all employees.
  • Prepare the response to requests for access, rectification and opposition.

What DimaCard provides

  • Exportable (CSV) and deletable customer file, to meet access and opposition rights.
  • Anti-fraud QR + PIN to secure points against cheating.
  • Hosting in the European Union and payment via Stripe, governed by our privacy policy.

Responsibility for processing rests with you: clear purpose, consent for marketing, customer information. DimaCard gives you the tools; the compliance of the processing remains yours.

Law 09-08 and GDPR: the same logic, two frameworks

The two texts share a basic logic – consent, purpose, individual rights, security – but remain two distinct frameworks, with different authorities and formalities (CNDP on one side, CNIL on the other). A trader who operates on both sides must therefore reason about both, without assuming that conformity to one is equivalent to conformity to the other. For the European framework, consult the GDPR and loyalty program checklist.

Conclusion

Law 09-08 is not an obstacle to loyalty: it is a framework of trust between the merchant and his customer. By retaining the essentials — purpose, consent for marketing, information, rights of access and opposition, and formalities to be verified with the CNDP — you cover most of the risk. To start a compliant program, request a demo via the contact page. If you have any specific doubts, contact the CNDP or legal advice.

Key Takeaways

  • Law 09-08 applies to any processing of personal data, including a loyalty program that records name and visit history.
  • The CNDP is the supervisory authority; it receives the preliminary formalities (declaration, even authorization) for certain treatments.
  • The basic principles: purpose, minimization, consent for marketing, information and rights of access, rectification and opposition.
  • DimaCard provides the tools (file export and deletion, QR + PIN anti-fraud, EU hosting), but the responsibility for processing remains with the merchant.
  • Law 09-08 and GDPR share a common logic but remain two distinct frameworks; This guide is general information, not legal advice.

Frequently Asked Questions

Does Law 09-08 apply to a loyalty program?

Yes. A loyalty program collects data linked to an identifiable person (name, telephone number, visit history): this is data processing subject to law 09-08.

What is the CNDP?

The National Commission for the Control of Personal Data Protection is the Moroccan authority responsible for ensuring compliance with Law 09-08.

Is customer consent required?

For marketing prospecting (offers, reminders, notifications), yes: the consent of the person is the expected basis. The operation of the program itself is based on its purpose.

Should the treatment be declared to the CNDP?

Law 09-08 provides for formalities (declaration, even authorization) for certain treatments. Verify the specifics of your program with the CNDP or a board rather than assuming compliance.

Does DimaCard ensure compliance for me?

No. DimaCard provides the tools (export and deletion of the file, anti-fraud QR + PIN, EU hosting), but the responsibility for the processing rests with you: purpose, consent and customer information. Find all the questions on the DimaCard FAQ.

Put it in place with DimaCard

Loyalty card in Apple & Google Wallet, included notifications, an independent loyalty prize wheel, and built-in referrals — starting at €39/month. The first paid subscription is covered by the 30-day commercial guarantee under the Terms.

See plans

More from the blog