Expertise compliance

WhatsApp API and the CNDP: The Essential Compliance Guide for Morocco (Law 09-08)

CNDP filing, Article 10 consent, STOP handling, retention, processor contracts and the data transfer to Meta (United States): the article-by-article guide to running WhatsApp Business API in Morocco without exposure to Law 09-08 sanctions.

WhatsApp API and the CNDP: The Essential Compliance Guide for Morocco (Law 09-08)

Why WhatsApp Business API is a “processing of personal data” under Law 09-08

A mobile number identifies a natural person. The moment your company stores it to message that person on WhatsApp, you are carrying out a processing of personal data within the meaning of Article 1 of Law 09-08 (Dahir 1-09-15 of 18 February 2009). The channel is irrelevant: what the law regulates is the contact database, the purposes you use it for, and the providers you hand it to.

A WhatsApp Business API integration combines at least four operations the CNDP looks at separately:

  • collecting the number (web form, order, appointment booking, Click-to-WhatsApp ad);
  • sending outbound messages, including marketing campaigns that qualify as direct marketing (Article 10);
  • receiving and archiving inbound conversations (inbox, chatbot, voice transcription);
  • transmitting numbers and content to processors: your messaging platform, then Meta, whose Cloud API hosts messages outside Morocco.

Each triggers a specific obligation. This guide takes them one by one, with the article number and the CNDP form that applies, because “CNDP compliant” printed on a sales page will not protect you during an audit. It complements our CNDP and ANRT guide for SMS and our GDPR vs Law 09-08 comparison.

Who is responsible for what: you, the platform, Meta

The law distinguishes the data controller, who decides purposes and means, from the processor, who acts on the controller's instructions (Article 23). On WhatsApp Business API the chain never changes, and Meta says so in its WhatsApp Business Data Processing Terms: the business is the Controller, WhatsApp the Processor.

PartyRole under Law 09-08Duties
Your companyData controllerFile with the CNDP, inform, collect consent, honour STOP, set retention, contract with processors
EnvoiSMS.ma (or any BSP)Processor (Art. 23)Act on instructions, secure the data, sign a written contract, keep the opt-out registry, allow export and erasure
Meta / WhatsAppSub-processorRoute and host messages; its terms make the business the Controller and include an international transfer addendum

Practical consequence: no provider can be compliant on your behalf. The filing receipt is issued in your name, the opt-in evidence belongs to you, and Article 64 targets your legal entity. A good processor gives you the tooling and the contract; it does not replace your filing.

Obligation 1 — File the processing with the CNDP before the first message

Article 12 subjects every processing to a prior declaration, or to prior authorisation in sensitive cases. The CNDP issues the receipt within 24 hours (Article 19) and may, within 8 days, reclassify the file under the authorisation regime if the processing shows manifest risks (Article 20). Without a receipt you fall under Article 52.

The current forms are published on the CNDP's notification procedures page (2025 nomenclature):

FormWhen it applies to WhatsApp
F214 — declaration under a framework decisionYour use matches a model: customer management (deliberation 32-2015) or newsletters (deliberation D-940-2025). The usual case for notifications and campaigns to existing customers
F211 — standard declarationOutside the models: prospecting non-customers, lead-qualification chatbot, extended conversation archiving
F112 / F113 — prior authorisationSensitive data (health, opinions, national ID number), reuse for a new purpose, file interconnection, profiling
F118 — transfer abroadTo be filed at the same time as the declaration, since Meta hosts the data outside Morocco (see obligation 7)

Two framework decisions are worth reading before completing the F214. Deliberation 32-2015 (customer management) explicitly allows “prospecting and promotion actions towards customers in compliance with Article 10” and lists the admissible data (identity, phone, purchase history, correspondence). Deliberation D-940-2025 (newsletters, 28 November 2025) is the closest model to a WhatsApp broadcast list: tick-box consent, unsubscribe in every message, retention until unsubscription, and one decisive reminder: “any use of the subscriber's data to build a personal profile requires prior authorisation”. A chatbot that scores your leads is therefore not covered by a plain declaration.

The 2025 F214 form states that the receipt “attests to registration” and “does not constitute operational validation”: the CNDP may audit on documents or on site and withdraw the receipt. Filing is the starting point, not a certificate.

Obligation 2 — Inform: what your opt-in form must state (Article 5)

Anyone asked for their data must be informed “expressly, precisely and unambiguously”, before collection. Article 5 lists the notices, and Article 19 adds a requirement almost nobody applies on WhatsApp: the receipt details “must appear in all data collection or transmission operations”.

Your form, checkout page or first message must therefore state:

  1. the controller's identity (your company name, not the provider's);
  2. the purposes: order notifications, appointment reminders, commercial offers, each named;
  3. the recipients or categories of recipients, including the transfer to Meta abroad (deliberation D-940-2025 requires naming transfers “duly authorised by the CNDP”);
  4. whether answering is mandatory or optional;
  5. the rights of access, rectification and objection, with a contact to exercise them;
  6. the CNDP receipt number for the processing.

That last item is the simplest test an inspector can run: a form with no receipt number means either you did not file or you do not inform. Either way Article 5 is not met.

Obligation 3 — WhatsApp consent: what Article 10 says and what Meta requires

Article 10 prohibits “direct marketing by means of an automated calling machine, a fax or electronic mail or any means using a technology of the same nature” without prior consent. WhatsApp falls into that last category: the 2009 text does not name it, but it was drafted to cover channels to come. Consent is defined as “any free, specific and informed expression of will” — a pre-ticked box, a number scraped from a website or a purchased list does not qualify.

Article 10 carries a single exception, modelled on European law: marketing to an existing customer whose details were collected directly during a sale, for similar products, provided a simple, free objection is offered at collection and in every message. It helps for e-commerce follow-ups; it covers neither a prospect who merely asked for a quote nor a contact imported from a third-party CRM.

The table maps Meta's four message categories to the Moroccan legal basis:

Meta categoryExampleLegal basis, Law 09-08Prior opt-in?
MarketingPromotion, cart recovery, launchConsent, Art. 4 and Art. 10Yes, specific to WhatsApp marketing
UtilityOrder confirmation, delivery tracking, appointment reminderPerformance of the contract, Art. 4-bNo, but Art. 5 notice and Art. 9 objection
AuthenticationOTP codePerformance of the contract / account security, Art. 4-bNo, but the number must come from the user
ServiceReply within 24h to an inbound messageThe inbound message embodies the request, Art. 4-bNo, to answer that request only

Two traps recur in audits. A message Meta bills as utility that slips in a commercial offer is direct marketing under Article 10 whatever its billing category. And a service conversation opened by the customer is not a marketing opt-in: answering a question does not authorise adding the number to next month's broadcast.

Compliant opt-in wording (French and Darija) and the evidence to keep

An opt-in is only worth what you can prove, dated and tied to a number. Three wordings satisfy Articles 10 and 5 in one sentence; adapt them with your company name and receipt number.

Web form or point of sale (box not pre-ticked):

☐ I agree to receive offers and news from [Company] on WhatsApp at the number provided. My data is processed for this purpose (CNDP receipt no. …), transmitted to our messaging provider and to Meta (United States) for delivery, and kept until I unsubscribe. I can unsubscribe at any time by replying STOP or via privacy@…

First WhatsApp message after an order (utility, no marketing opt-in):

Hello Sara, your order no. 4821 is confirmed. Delivery updates will arrive on this number. Would you also like our offers? Reply YES. Reply STOP to receive no further messages. [Company] — CNDP receipt no. …

Darija version (same structure):

Salam Sara, la commande dyalek n° 4821 tconfirmat. Ghadi twsslek l-livraison f had raqm. Bghiti tosslek l-3oroud dyalna ? Jawbi OUI. Jawbi STOP bach ma yosslekch walo. [Company] — CNDP n° …

What to record for every consent, in a registry you can export:

  • the number in international format and the exact timestamp;
  • the source: form (URL), YES reply (WhatsApp message id), Click-to-WhatsApp ad, signed import;
  • the exact text shown to the person at the moment of consent;
  • the purpose consented to: marketing, notifications, OTP — one entry per purpose;
  • any withdrawal, with its date and channel.

A CRM screenshot is not enough: it proves a state, not an event. That is why EnvoiSMS.ma exposes a consent registry API (/v1/consents) that timestamps every grant and every withdrawal, including those received automatically by keyword on WhatsApp, and returns them per number for an access request or an audit.

Obligation 4 — STOP: objection must work inside the message itself

Article 9 gives everyone the right to object “free of charge” to the use of their data for marketing. Article 10 spells out the electronic-channel requirement: every marketing message must show “valid contact details to which the recipient can usefully send a request” to stop, and hiding the sender's identity is prohibited. Ignoring an objection is punished under Article 59.

On WhatsApp that means four rules:

  1. Every marketing template carries a readable unsubscribe line (“Reply STOP”) or a dedicated quick-reply button. Meta itself requires it to approve some marketing templates.
  2. The keyword is handled immediately and without a human: STOP, ARRÊT, إلغاء, BAJA and their variants must block the number for every subsequent campaign, on WhatsApp and on SMS alike.
  3. An objected number is never re-imported by a CRM sync or a campaign file; the suppression list overrides any send list.
  4. The withdrawal is logged with its date, because an untracked STOP replays at the next import.

Objection does not erase the number: it places it on a suppression list you must precisely keep to prove you honour it. Our anti-spam policy and the /v1/optouts endpoint describe the platform mechanics.

Obligation 5 — Set and keep a retention period

The law gives no universal number; it requires the period to be declared and respected. Article 55 punishes retention “beyond the period provided by the legislation in force or the one stated in the declaration”. The two framework decisions give the benchmark: deliberation 32-2015 limits retention to “what is necessary to manage the commercial relationship”, with archiving allowed for contractual proof or legal duties; deliberation D-940-2025 keeps subscribers “until the unsubscription request”.

A defensible policy for WhatsApp Business API:

DataRecommended periodBasis
Number + marketing consentUntil withdrawal, purging inactive contacts after 24–36 monthsD-940-2025, Art. 10
Conversation content (support, chatbot)12 rolling months, then anonymisationService purpose, Art. 3-e
Send logs and delivery receipts30–90 days in clear, then aggregatedSecurity and billing
OTP codesThe code's validity window (minutes)Authentication purpose
Opt-in and opt-out evidenceWhole relationship + 3 yearsEvidence for audits or disputes

Write these periods into your declaration, your privacy policy and your tool settings. Our public DPA states the periods applied platform-side, so you never declare a period your provider does not keep.

Obligation 6 — Security and processors (Article 23): the DPA is not optional

Article 23 requires “appropriate technical and organisational measures”, then regulates outsourcing in three steps: choose a processor “offering sufficient guarantees”, bind it by a written contract obliging it to act only on instructions, and record in writing the security requirements “for evidential purposes”. Article 58 punishes missing measures; Article 61 targets the processor itself, “even through negligence”.

Before sending your first template, check that your WhatsApp platform provides:

  • a data processing agreement, signed or acceptable online, naming roles, retention periods and sub-processors — ours is public: Data Processing Agreement;
  • a sub-processor list with locations, kept up to date with notice — ours;
  • encryption in transit and at rest, named and logged access, an incident notification procedure;
  • export and erasure mechanisms on request, without a manual ticket;
  • an activity log of your WhatsApp Business account (who edited a template, connected a number, disabled the bot).

A provider that answers “we are CNDP compliant” without handing you a contract does not make you compliant: the missing written record is exactly what Article 23-4 targets.

Obligation 7 — The transfer to Meta (United States): the point everyone forgets

This is the most ignored obligation on the market, and the heaviest. Article 43 only allows transfers to a State “ensuring a sufficient level of protection”, on a list set by the CNDP. That list, fixed by deliberation 236-2015, holds 32 countries: the EU and EEA States, Switzerland, the United Kingdom and Canada. The United States is not on it.

Meta's documentation states that the Cloud API stores data in the United States by default, and that local storage is offered only for about ten markets (Australia, Indonesia, India, Japan, Singapore, South Korea, Germany for the EU, Switzerland, United Kingdom). Morocco is not among them. Every WhatsApp message you send to a Moroccan customer through the official API is therefore a transfer to a non-listed country, whatever the intermediary provider.

The law offers three ways out, in Article 44:

  1. The person's express consent to the transfer — hence the “transmitted to Meta (United States)” clause in the opt-in wordings above. The simplest basis for marketing, since you already collect consent.
  2. Contractual necessity (Art. 44-1-d): an order confirmation or an OTP is necessary to perform the contract with the person. This covers utility and authentication messages, not marketing.
  3. An express, reasoned authorisation from the CNDP (Art. 44-3) where the processing offers sufficient guarantees “by reason of contractual clauses”. Meta's Data Processing Terms incorporate an international transfer addendum; that is the document to attach.

In every case the transfer is notified with form F118 — the F214 form itself reminds you that a transfer “must be the subject of a simultaneous request”, and deliberation D-940-2025 forbids any transfer “without prior authorisation from the CNDP”. The F118 asks for the recipient, the country, the purpose, the frequency, the date of the first transfer and the receipt number of the underlying processing; the CNDP decides within two months, extendable once.

An unlawful transfer is the Article 60 offence: three months to one year of imprisonment and a fine of MAD 20,000 to 200,000, doubled for a legal entity. No platform, Moroccan or foreign, can remove that transfer as long as Meta offers no local storage in Morocco; the only honest compliance is to declare it and ground it on Article 44.

What you risk: the sanctions, article by article

The CNDP publishes the official list of offences and sanctions. Applied to a WhatsApp Business API project, these are the ones that bite most directly. Amounts are in dirhams; Article 64 doubles fines for a legal entity and adds business closure and confiscation; Article 65 doubles again for repeat offences.

FailureArticleSanction
Sending without declaration or authorisation52MAD 10,000–100,000
Refusing access, rectification or objection53MAD 20,000–200,000 per offence
Unfair collection or use for undeclared purposes (e.g. support numbers reused for marketing)543 months–1 year prison and/or MAD 20,000–200,000
Retaining beyond the declared period553 months–1 year and/or MAD 20,000–200,000
Processing without consent (Art. 4)563 months–1 year and/or MAD 20,000–200,000
Sensitive data (health, national ID) without express consent573 months–1 year and/or MAD 50,000–300,000
No security measures (Art. 23-24)583 months–1 year and/or MAD 20,000–200,000
Marketing despite objection (ignored STOP)593 months–1 year and/or MAD 20,000–200,000
Transfer abroad outside Articles 43-44603 months–1 year and/or MAD 20,000–200,000
Misuse or disclosure to unauthorised third parties, even by negligence (also targets the processor)613 months–1 year and/or MAD 20,000–200,000, seizure of equipment
Obstructing a CNDP audit623–6 months and/or MAD 10,000–50,000

Since 2025 the CNDP has announced targeted sector audits — hospitality, healthcare, e-commerce, higher education — precisely the sectors that adopted WhatsApp Business API fastest. The pending reform of Law 09-08 aims at GDPR alignment (legal bases, DPO, breach notification, sanction levels); the obligations described here will only tighten.

1 October 2026: Meta's new Morocco rate card also changes the compliance maths

Meta has announced that Morocco leaves the regional “Rest of Africa” pricing for a standalone rate card on 1 October 2026, with higher utility and authentication rates, a new authentication-international rate, and billing of service messages (free-form, inside the 24-hour window) beyond a monthly allowance per number. The figures below are those relayed by BSPs from Meta's cards; the official per-currency rate card prevails and must be checked before budgeting.

CategoryBefore 1 Oct 2026 (Rest of Africa)Announced for Morocco, 1 Oct 2026Indicative equivalent
Marketing$0.0225$0.0414≈ MAD 0.39
Utility$0.0040$0.0230≈ MAD 0.21
Authentication$0.0040$0.0230≈ MAD 0.21
Authentication-international$0.0811≈ MAD 0.75
Service (free-form)FreeUtility rate after 1,000 messages/number/month≈ MAD 0.21

Why this belongs in a compliance guide: Meta classifies templates by category and checks it at approval. A marketing message disguised as utility to save a few cents will be reclassified by Meta, and it remains direct marketing under Article 10 — you stack pricing risk on legal risk. Conversely, a service conversation opened by the customer is both the cheapest and the most legally solid: the request comes from the person. Designing journeys so the customer writes first (website button, QR code, Click-to-WhatsApp ad with its free 72-hour window) is the best compliance and cost decision of 2026.

On EnvoiSMS.ma billing stays in dirhams, 0.65 MAD per notification and 1.15 MAD per marketing message, with no subscription and each template's category visible in the dashboard.

WhatsApp API × CNDP compliance checklist (12 points)

To validate before go-live, then review for every new use case:

  1. Declaration filed (F214 or F211) in the company's name, receipt received and archived.
  2. F118 filed for the transfer to Meta, with the Article 44 basis identified (express consent, contract, or authorisation).
  3. Receipt number shown on every collection medium (form, terms, first message).
  4. Complete notices: controller, purposes, recipients including Meta, rights, contact.
  5. WhatsApp-specific marketing opt-in, box not pre-ticked, wording kept.
  6. Timestamped consent registry, exportable per number, also fed by YES/STOP replies.
  7. Working STOP on every marketing template, multilingual, handled automatically, propagated to SMS.
  8. Purpose separation: a number collected for support does not enter campaigns without fresh consent (Art. 54).
  9. Retention periods written in the declaration and enforced by the tool.
  10. Signed DPA with the platform, sub-processor list checked.
  11. Rights procedure: answer an access or erasure request within 30 days, with a real data export.
  12. Prior authorisation obtained before any scoring, profiling or health data processing by the chatbot.

If a single point is missing, fix it before launch: the sanctions of Articles 52 to 61 accumulate, they do not substitute.

How EnvoiSMS.ma equips you, point by point

We are a processor, not the controller: we cannot file your declaration, but we can make every obligation verifiable from your account.

ObligationWhat the platform provides
Processor contract (Art. 23)Public DPA and sub-processor list, with 30 days' notice
Proof of consent (Art. 10)Consent registry GET/POST /v1/consents, fed automatically by YES/START and STOP keywords received on WhatsApp and SMS, exportable per number
Objection (Art. 9)/v1/optouts suppression list shared between WhatsApp and SMS, multilingual STOP keywords handled instantly
Access and erasure rights (Art. 7-8)Full JSON export and self-service erasure request from Settings, handled within 30 days
Meta categories and Article 10Every template carries its category (marketing, utility, authentication); the dashboard separates customer-opened conversations (24-hour window)
Traceability (Art. 23-24)WhatsApp Business account activity log and API access audit log
Transfer (Art. 43-44)Roles and transfer mechanism described in the DPA, to attach to the F118

To connect your number to the official API, the WhatsApp Business API in Morocco page walks through Meta Embedded Signup; for full costs, read WhatsApp Business API pricing in Morocco.

💡 Why choose EnvoiSMS for your business?

Carrier Delivery

Local routes to IAM, Orange and Inwi, with automatic failover between routes and delivery status sent by webhook.

💰

Cost Optimization

WhatsApp Business API from 0.65 MAD per message with optimal ROI.

🛡️

Sovereign Data (CNDP)

Full compliance with Moroccan personal data protection regulations (CNDP).

Q.Do I need to file with the CNDP if I only use WhatsApp to confirm orders?
Yes. Order confirmation needs no marketing opt-in (contractual basis, Article 4-b), but the file of numbers remains a processing subject to declaration (Article 12). The F214 “customer management” model (deliberation 32-2015) is designed for this case, and the transfer to Meta must be notified at the same time with the F118.
Q.Has a customer who messages me on WhatsApp consented to my campaigns?
No. Their message opens a service conversation and allows you to reply; it is not the “free, specific and informed” consent Article 10 requires for marketing. Ask explicitly (“Reply YES to receive our offers”) and record the answer.
Q.Does the CNDP recognise the United States as a country with sufficient protection?
No. The deliberation 236-2015 list covers the EU and EEA States, Switzerland, the United Kingdom and Canada. A transfer to Meta must therefore rest on Article 44 (express consent, contractual necessity or CNDP authorisation) and be notified with form F118.
Q.Can I use a foreign platform (Twilio, 360dialog, Wati) and stay compliant?
The framework is identical: you remain the controller, the provider is a processor (Article 23) and Meta remains a recipient in the United States. A foreign provider adds a second transfer to declare on the F118 and a contract often governed by foreign law; check that it will sign a processing agreement compliant with Law 09-08.
Q.What retention period should I declare for WhatsApp contacts?
The law requires a declared and respected period, with no imposed figure. The framework decisions use “until unsubscription” for a broadcast list and “the duration of the commercial relationship” for customers. A common policy: marketing contacts until withdrawal with purge of inactives after 24–36 months, conversations 12 months, opt-in evidence for the whole relationship plus 3 years.
Q.My chatbot qualifies leads: is a plain declaration enough?
Not if the bot builds a profile or a score of the person. Deliberation D-940-2025 recalls that profiling requires prior authorisation (Article 12), as do health data or the national ID number. File an F112 before enabling that kind of processing.
Q.What does an SME actually risk by sending WhatsApp campaigns without opt-in?
Article 56 (processing without consent) and Article 59 (marketing despite objection) each carry three months to one year of imprisonment and/or MAD 20,000–200,000, doubled for a legal entity (Article 64). Add Article 52 if the file is undeclared and Article 60 if the transfer to Meta is not covered.
Q.Does Meta's 1 October 2026 pricing change alter my obligations?
Not in substance, but it makes cheating on template category more expensive: a marketing message filed as utility will be reclassified by Meta and remains marketing under Article 10. Design journeys so the customer writes first; it is the strongest legal basis and the cheapest category.

Suggested Articles

SMS Regulations in Morocco: ANRT Directives & CNDP Compliance
compliance

SMS Regulations in Morocco: ANRT Directives & CNDP Compliance

CNDP Guide 2026: How to Send SMS Legally in Morocco
compliance

CNDP Guide 2026: How to Send SMS Legally in Morocco

Morocco Telecom Review: 12 Months of Enterprise Messaging Insights
market

Morocco Telecom Review: 12 Months of Enterprise Messaging Insights