cashod
GUIDES

Law 09-08 and customer data: a CNDP guide for online stores

CNDP declaration, privacy notice, marketing consent, subcontractors and penalties: what Morocco’s law 09-08 requires of an online store, article by article.

Cashod Editorial TeamGuides for COD sellers11 min read
Law 09-08 and customer data: a CNDP guide for online stores
Table of Contents

Every cash-on-delivery order carries a name, a phone number and a home address. In Morocco, that is personal data under law 09-08, and the seller who decides what happens to it answers for it before the national data-protection authority, the Commission nationale de contrôle de la protection des données à caractère personnel (CNDP). This guide goes through what the law asks of an online store, one obligation at a time, with the article of the law and the CNDP page behind each. It is a practical reading of the texts, not legal advice: for a specific case, the CNDP itself offers support, described further down.

What law 09-08 covers in a COD store

The CNDP defines personal data as information that identifies a natural person directly or indirectly: first and last name, postal or email address, phone number, bank card number, photo, the computer’s IP address. An order record holds most of these. So do a confirmation agent’s call notes, the file sent to the carrier and the list of buyers you retarget with ads.

The law calls whoever decides the purposes and means of the processing the “controller” (responsable du traitement). For a store, that is the seller: the company, or the individual entrepreneur trading in their own name. The store platform, the carrier and the call center process the data too, but the main obligations fall on you.

The law has not stayed on paper. In July 2023, the CNDP’s president told Médias24 that the commission was moving from the teaching phase to the strict application of the law. In May 2025, Hespress reported that the commission was writing to companies to remind them of their obligation to notify their data processing, with a warning about sanctions. In August 2026 it was still citing law 09-08 article by article in its guidance for the legislative elections. The implementing text is decree no. 2-09-165, published alongside the law in the CNDP’s regulatory section.

Consent or contract: the basis for processing order data

Article 4 of law 09-08 makes consent the rule but lists exceptions. The CNDP summarises them on its page on people’s rights: consent is not required when the processing is part of performing a contract to which the person is party, when it meets a legal obligation, or when it serves a legitimate interest that does not override the person’s rights.

For a COD store this draws a clear line. Calling customers to confirm the order they just placed, passing their address to the carrier, keeping the invoice: all of that performs the sale. Using the same phone number to push next week’s promotion is a different purpose with its own rules, covered below.

Article 3 adds principles that apply in every case. Data must be collected for specified, explicit and legitimate purposes; be adequate, relevant and not excessive; be accurate; and be kept no longer than the purpose requires. In practice:

  • Ask only for what delivery needs: name, phone, city, address. A field added “just in case” is excessive data.
  • Do not ask for the national ID card number. The CNDP places processing of data that include the national identity card number among the cases that need prior authorisation, not a simple declaration.
  • Do not swap a “blacklist” of customers who refused parcels with other sellers. Article 4 allows data to be passed to a third party only for purposes directly linked to the functions of both parties, and subject to the person’s prior consent.
  • Decide how long you keep order records and write it down: the declaration to the CNDP has to state it.

Tell customers on the order form

Article 5 requires that anyone asked for their data be told, expressly and precisely, before it is collected. The CNDP lists what the collection medium must show: the identity of the controller, the purposes and the recipients, how people can exercise their rights, whether answers are compulsory, and the references of the receipt or authorisation issued by the CNDP.

In a store, the collection medium is the order form on the sales page and the platform’s checkout, but also the WhatsApp chat or phone call in which an agent collects a missing address. A short notice under the order button, linked to a full privacy page, covers the form. The CNDP publishes model notices, including one for paper and online forms. Adapted to a store, it reads roughly like this:

“Through this form, [store or company name] collects your personal data in order to process and deliver your order. This processing has been declared to the CNDP under number [receipt number]. Your data are shared with [carrier, call center…]. You can exercise your rights of access, rectification and opposition by writing to [email or phone], in accordance with law 09-08.”

Two practical points. The notice has to match reality: if a call center in another city or a tool hosted abroad sees the data, say so. And the receipt number only exists once you have declared, which is the next step.

Declare to the CNDP before you start

The CNDP states the rule plainly: all processing must be declared in advance, except processing excluded from the law, exempted, or subject to authorisation. Its FAQ adds that public and private bodies may start processing only after receiving the declaration receipt or a written authorisation. In 2026 it again pointed to article 12 as the source of this duty.

Online selling has a track of its own. The CNDP adopted deliberation no. 508-AU-2014, a model declaration for processing linked to online sales, filed on form F-214, the declaration made in line with a CNDP decision. Customer management has its own model (deliberation no. 32-2015). Two newer models, adopted in November 2025, cover cookies on a website (deliberation D-939-2025) and newsletters (D-940-2025). Processing that fits no model goes on the standard declaration form, F-211.

For online sales, the CNDP asks in particular for a copy of the document that collects consent or states another legal basis, a copy of any subcontracting contract with confidentiality clauses, and a document showing the signatory’s authority. On timing, it says it issues the declaration receipt within 24 hours, and notifies within eight days if it decides the processing needs prior authorisation instead.

If you are unsure which form applies, the CNDP offers a support request form to use before filing, and a phone line, 3020.

Carriers, call centers and tools: who else sees the data

A COD order passes through several hands: the store platform, a spreadsheet, the order-management software, the confirmation team, the carrier. Article 23 of the law requires the controller to choose subcontractors that give sufficient security guarantees and to bind them by contract. In 2026 the CNDP repeated the need to govern subcontracting with contracts that comply with law 09-08 (articles 23 and 25). The contract must state that the subcontractor acts only on your instructions and carries the same security obligations.

The CNDP’s model subcontracting clause spells out the content: keep the data secure, process it only on instructions, no further subcontracting without approval, destroy the data when the contract ends. Ask your outsourced call center, your freelance agents and your software providers for these commitments. Carriers receive name, phone and address in order to deliver: name them as recipients in your notice and declaration, and check what their contract says about confidentiality.

Many tools sellers rely on store data outside Morocco. A transfer abroad is allowed only in the cases listed in articles 43 and 44 of law 09-08: to a country on the CNDP’s list (amended by deliberation no. 236-2015), or elsewhere with the person’s express consent, where it is needed to perform the contract with them, or with CNDP authorisation. Requests go on form F118, and a transfer authorisation is granted only when the underlying processing has itself been declared or authorised.

Promotions by SMS, email or WhatsApp

Confirming an order is not marketing; sending an offer is. Article 10 bans direct marketing by automated calling machine, fax, email or any means using a similar technology to people who have not given prior consent. In 2026 the CNDP again warned against direct marketing without prior consent under article 10. Its sheet on SMS and email marketing sets two conditions: the recipient’s prior consent, and a declaration of the processing to the CNDP before it starts.

There is one exception. According to that sheet, prior consent is not required if you collected the contact details from the person during an earlier sale of similar products or services, provided they can object free of charge when the details are collected and in every message. In every case:

  • give a working way to stop the messages (a number, an address, a link); Médias24, reporting the CNDP’s position, notes that a “StopSMS” link must appear in the message the recipient receives;
  • do not hide who is sending, and do not use a subject line unrelated to the offer;
  • never buy a file of phone numbers without checking how it was built: the CNDP sheet asks you to make sure a provider’s database was lawfully put together.

WhatsApp is not named in the law, but the ban covers “a means using a technology of the same nature”. A promotional WhatsApp broadcast to past buyers is safer treated as falling in the same category. Our guide to automated WhatsApp order confirmation explains how to keep confirmation and promotion apart.

Answer requests and keep the files safe

Customers keep three rights over their data, summarised on the CNDP’s rights page: access, free of charge and without delay; rectification, which the controller must carry out free of charge and within ten clear days at most; and opposition, at any time, on legitimate grounds and at no cost. If you refuse or stay silent, the person can turn to the CNDP, which takes complaints online, by email or in person.

Set up a single channel for these requests (an email address or the store’s WhatsApp number) and one person who answers them. A customer who asks “why do you have my number?” should get the source and the purpose, not silence.

Article 23 also requires technical and organisational measures suited to the risks, against loss, alteration, disclosure and unauthorised access. In a COD business, the usual leaks are mundane:

  • order exports passed around WhatsApp groups and never deleted;
  • one shared login for every agent, still known to people who have left;
  • spreadsheets shared with “anyone who has the link”;
  • customer lists stored on agents’ personal phones.

Give each person their own account, limited to their work; remove access on the day someone leaves; delete exports once the carrier has the file. The law also binds everyone who handles the data to professional secrecy, even after they leave the job, so write it into agents’ contracts.

What non-compliance costs

BreachPenalty
Processing without declaration or authorisation (article 52)Fine of MAD 10,000 to 100,000
Refusing access, rectification or opposition (article 53)Fine of MAD 20,000 to 200,000 per breach
Unfair or unlawful collection, use for another purpose (article 54), keeping data too long (article 55), processing without consent where it is required (article 56)Three months to a year in prison and/or a fine of MAD 20,000 to 200,000
Sensitive data, such as health, without express consent (article 57)Three months to a year in prison and/or a fine of MAD 50,000 to 300,000
Processing without the required security measuresThree months to a year in prison and/or a fine of MAD 20,000 to 200,000

These amounts come from chapter VII of the law and are set out by Médias24. When the offender is a company, fines are doubled, and repeat offences double the penalties too. Hespress described what follows a complaint: the CNDP first sends a warning to the controller to put things right, organises on-site visits if nothing changes, and can go as far as sending the case to the public prosecutor.

A compliance checklist for a COD store

  1. List your processing: orders and delivery, confirmation by phone and WhatsApp, customer service, marketing, cookies and ad pixels.
  2. For each one, note the purpose, the data, the recipients, the retention period and any transfer abroad.
  3. Cut the order form down to what delivery needs; drop the ID card number.
  4. Add the notice to every form, plus a full privacy page.
  5. File the declarations (online-sales model, cookies, newsletter if you send one) and add the receipt numbers to your notices.
  6. Sign subcontracting clauses with your call center, agents and software providers; check where your tools host data.
  7. Keep customers who agreed to receive offers apart from the rest, and put an opt-out in every promotional message.
  8. Create one channel for access, rectification and opposition requests.
  9. Close shared logins and old exports; give each agent their own access.
  10. Review all of this whenever you add a tool, a store or a market.

If you trade as an auto-entrepreneur, the law applies in the same way; our guide to the auto-entrepreneur status for online sellers covers the rest of your obligations. For the confirmation call itself, see our article on confirming COD orders.

Where Cashod fits

Cashod includes a call center where agents confirm COD orders by phone, and can confirm orders over WhatsApp, including with an AI agent. One Cashod account can manage several stores.

Whatever tool you use, the obligations above stay with the seller as controller: the notice, the declaration, the choice of what to collect and how long to keep it. If your confirmation runs by phone and over WhatsApp, describe both channels in your notice and declaration as part of order processing. If one account runs stores that belong to different companies, each company is the controller for its own customers and declares its own processing.

Cashod support answers by email, chat and phone, Monday to Friday, 9 AM to 6 PM GMT (Morocco time).

Tags
CNDPloi 09-08données personnellesconformitéMaroc
Written byCashod Editorial TeamGuides for COD sellers
Share
Back to blog

Grow Your COD Business

Start free trial

7-day free trial · Cancel anytime