Why WhatsApp Business API is a “processing of personal data” under Law 09-08
A mobile number identifies a natural person. The moment your company stores it to message that person on WhatsApp, you are carrying out a processing of personal data within the meaning of Article 1 of Law 09-08 (Dahir 1-09-15 of 18 February 2009). The channel is irrelevant: what the law regulates is the contact database, the purposes you use it for, and the providers you hand it to.
A WhatsApp Business API integration combines at least four operations the CNDP looks at separately:
- collecting the number (web form, order, appointment booking, Click-to-WhatsApp ad);
- sending outbound messages, including marketing campaigns that qualify as direct marketing (Article 10);
- receiving and archiving inbound conversations (inbox, chatbot, voice transcription);
- transmitting numbers and content to processors: your messaging platform, then Meta, whose Cloud API hosts messages outside Morocco.
Each triggers a specific obligation. This guide takes them one by one, with the article number and the CNDP form that applies, because “CNDP compliant” printed on a sales page will not protect you during an audit. It complements our CNDP and ANRT guide for SMS and our GDPR vs Law 09-08 comparison.


