Encryption Law by Country
Where strong encryption is a right, restricted, or compelled. National law and policy, mirrored per country.
Source: Global Partners Digital, World Map of Encryption, updated 2026-07-02. Full data at www.gp-digital.org/world-map-of-encryption
Encryption Law by Country (196)
General right to encryption
No known legislation or policies.
Mandatory minimum or maximum encryption strength
No known legislation or policies.
Licensing/registration requirements
Article 13 of Law No. 53-05 on the Electronic Exchange of Legal Data provides that, in order to prevent their use for illegal purposes and to preserve the interests of national defence and the internal or external security of state, the import, export, supply or use of cryptography means or services are subject either prior declaration or authorisation. Prior declaration is required where the sole purposes of the cryptography is to authenticate transmission, or ensure the completeness of data transmitted electronically. Prior authorisation, however, is required in all other purposes. Article 13 also gives the government the power to provide for simplified declaration or authorisation processes, and to exempt certain types of cryptography means or services from the requirements. Article 14 provides that where prior authorisation is required, such authorisation can only be granted to electronic certification service providers approved under Article 21, or persons approved by the government. Article 21 sets out the process for seeking approval, and states that it must be provided by a ‘national authority’ and that any providers seeking approval must be a company based in Morocco. Under Decree 2.13.1881, the ‘national authority’ is the Directorate General for Information Systems Security. The import, export, supply or use of cryptographic means or services without prior declaration or authorisation is a criminal offence, punishable by up to one year’s imprisonment and a fine of up to 100,000 MAD. A copy of the law (in Arabic) can be found here . A translation of the law (in French) can be found here . A copy of the decree (in Arabic) can be found here .
Import/export controls
Article 13 of Law No. 53-05 on the Electronic Exchange of Legal Data provides that, in order to prevent their use for illegal purposes and to preserve the interests of national defence and the internal or external security of state, the import, export, supply or use of cryptography means or services are subject either prior declaration or authorisation. Prior declaration is required where the sole purposes of the cryptography is to authenticate transmission, or ensure the completeness of data transmitted electronically. Prior authorisation, however, is required in all other purposes. Article 13 also gives the government the power to provide for simplified declaration or authorisation processes, and to exempt certain types of cryptography means or services from the requirements. Article 14 provides that where prior authorisation is required, such authorisation can only be granted to electronic certification service providers approved under Article 21, or persons approved by the government. Article 21 sets out the process for seeking approval, and states that it must be provided by a ‘national authority’ and that any providers seeking approval must be a company based in Morocco. Under Decree 2.13.1881, the ‘national authority’ is the Directorate General for Information Systems Security. The import, export, supply or use of cryptographic means or services without prior declaration or authorisation is a criminal offence, punishable by up to one year’s imprisonment and a fine of up to 100,000 MAD. A copy of the law (in Arabic) can be found here . A translation of the law (in French) can be found here . A copy of the decree (in Arabic) can be found here .
Other restrictions
Article 33 of Law No. 53-05 on the Electronic Exchange of Legal Data provides that, where encryption is used to commit a criminal offence, and the penalty is one of imprisonment, the maximum penalty for the offence is to be increased by between three and five years. Article 34 provides that where persons provide cryptography services for the purposes of confidentiality, they are liable in respect of any injury caused to persons using those services where there is a breach of the integrity, confidentiality or availability of their data. A copy of the law (in Arabic) can be found here . A translation of the law (in French) can be found here .
Obligations on individuals to assist authorities
No known legislation or policies.
Obligations on providers to assist authorities
No known legislation or policies.
Assessment Text Area
There is a higher penalty for crimes committed using encryption in Morocco and the law also provides that where there is a breach of the integrity, confidentiality or availability of data, those responsible for providing those services are liable for any injury caused. Further, the import, export, supply or use of cryptography means or services are subject either prior declaration or authorisation by the government.
Murphy's Law