Law 09-08: awareness, training & human risk

If your organisation processes personal data in Morocco, you are a data controller under Law No. 09-08 on the protection of individuals with regard to the processing of personal data — supervised by the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP). Filing your processing operations with the CNDP is the visible part of compliance; the part decided every day is what your employees do with the data flowing through their inboxes. This page explains what Law 09-08 actually expects on the human side of security, and how AfriPhish helps you produce evidence rather than promises.

What Law 09-08 requires on staff awareness and human risk

Law 09-08 contains no article titled "awareness programme". It contains something more demanding: obligations that can only be met through your people.

Prior formalities with the CNDP. Before any processing begins, the controller must complete the formalities the law prescribes: a prior declaration for most processing operations, and prior authorisation for the most sensitive categories. Those filings describe, among other things, the measures taken to secure the processing. In other words, you have already told the CNDP that your data is protected — the open question is whether you can demonstrate it on the day the Commission checks.

The security obligation (article 23). The controller must implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access. Organisational measures are, first of all, about people: a single employee typing credentials into a fake login page, or sending an HR file to the wrong recipient, bypasses every technical control you own. Phishing is an obvious risk for any Moroccan organisation with email — so a workforce that is untrained, or trained but never tested, is a gap in your article 23 measures.

Confidentiality of persons acting under your authority. The law requires that people with access to personal data in the course of their duties process it only on the controller's instructions and keep it confidential. Staff can only honour obligations they know about: documented training and formally signed policies turn that abstract duty of confidentiality into a traceable individual commitment.

CNDP inspections. The CNDP holds investigation and control powers, and non-compliance exposes controllers to sanctions, including criminal penalties. During an inspection, the Commission does not stop at the copy of your declaration — it looks at whether the declared measures exist in reality. A register of completed training, executed simulations and signed policies is exactly the kind of exhibit that separates asserted compliance from demonstrated compliance.

The obligations AfriPhish helps you evidence

AfriPhish is built around a simple principle: every awareness activity should leave an audit trail. Here is how the platform maps to Law 09-08's expectations.

Law 09-08 expectationAfriPhish moduleEvidence produced
Organisational measures (article 23)Security awareness training in French, Arabic and EnglishPer-user completion records, quiz scores, assignment dates
Declared measures actually effectivePhishing simulations across realistic scenario familiesClick, credential-submission and report rates, trended per campaign
Control of risks to processing operationsHuman risk scoringA per-user and per-department risk score that moves with behaviour
Confidentiality and instructed processingPolicy management with e-signature attestationVersioned, timestamped signature registers showing who acknowledged what
Fast reaction to incidentsSimulation reporting behaviour and real-time coachingRecords of who reports suspicious mail, and targeted coaching for those who do not
Readiness for a CNDP inspectionReports and analyticsExportable programme reports covering the whole awareness cycle

Because training completion, simulation outcomes and policy signatures live in one platform, you answer "show us your organisational measures" with a dated report, not a last-minute reconstruction.

What auditors and the CNDP typically ask for

When the CNDP, an external auditor, a parent company or a major client examines your human safeguards, the requests are predictable:

  • Training logs — who was assigned which module, who completed it, when, and with what assessment result.
  • A policy attestation register — which version of your IT charter or data protection policy each employee signed, with timestamps.
  • Simulation trend reports — evidence that you test staff against realistic phishing and that failure rates are measured and falling, not guessed at.
  • Reporting-channel records — proof that employees know how to escalate a suspected incident, and that reports actually flow.
  • Coverage of new joiners — evidence that awareness is continuous, not a one-off induction slide deck.

Every one of these artefacts is a standard export from AfriPhish. None needs to be assembled by hand the week before an inspection.

See where your organisation stands

Before you build or buy anything, measure. Take the free 4-minute Human Risk Maturity Assessment — it benchmarks your current awareness programme against what Law 09-08's security obligation implies, and tells you exactly where the gaps are.

Prefer to talk it through? Book a demo and we will walk through your CNDP evidence file together.