Skip to content

Using AI without exposing your company’s data: good practices and Law 09-08

What happens to your data in an AI tool, what Moroccan Law 09-08 says, and simple rules for your teams, with an AI usage policy.

Your teams already use AI to draft an email, summarize a contract or tidy up a customer spreadsheet. It often helps, but every copy and paste sends information outside the company, sometimes to servers located abroad. Here is how to get the benefits of AI while protecting your data in Morocco, and in particular while respecting Law 09-08.

What happens to the data you enter into an AI tool

When you paste text into an AI assistant, it leaves your computer. It is processed on the provider's servers, often outside Morocco. What happens next depends on the tool and its settings.

  • Many consumer tools keep a history of your conversations. Depending on the settings, those exchanges may be used to improve the provider's models.
  • The business offers from the main providers usually commit not to train their models on your data. They also add admin controls: account management, retention periods, activity logs.
  • In both cases, what counts is the terms of use and the account settings, not the impression the interface gives you.

Before you approve a tool, ask yourself three questions:

  • Where is the data processed and stored?
  • How long is it kept?
  • Can it be used to train a model, and how do you turn that off?

A common scenario: a salesperson pastes an Excel export into a free chatbot, with customer names, phone numbers and outstanding amounts, to "write a clean reminder." The reminder looks great. But the file now sits with a third party, and nobody in the company knows where, or for how long.

What Law 09-08 says, with CNDP sources

Law No. 09-08 of February 18, 2009 governs the protection of individuals with regard to the processing of personal data. Compliance is overseen by the Commission nationale de contrôle de la protection des données à caractère personnel, the CNDP. Its website provides the text of the law and the steps to follow.

Personal data is any information about an identified or identifiable individual: a name, a phone number, an email address, a national ID number, a photo. A customer list, a payroll file or a WhatsApp history with prospects almost always contains some.

The key principles to keep in mind:

  • Lawful and fair: data is collected and processed lawfully and fairly.
  • Specified purpose: you process it for a clear objective, without diverting it to an incompatible use.
  • Proportionality: only the data needed for that objective is used.
  • Limited retention: it is not kept longer than necessary.
  • Security: you put technical and organizational measures in place to protect it.

The people concerned also have rights: to be informed about the processing, to access their data, to have it corrected and to object to the processing.

On the administrative side, processing personal data generally requires a prior declaration to the CNDP. Some sensitive processing requires prior authorization. Finally, transferring personal data to a foreign country is regulated: depending on the level of protection offered by the destination country, it may require CNDP authorization.

That last point applies directly to AI. When an employee pastes customer data into a tool hosted outside Morocco, the company may end up transferring personal data abroad without having planned for it.

This summary is not legal advice: for your specific case, check with the CNDP or a legal advisor.

Simple rules for your teams

A few clear rules that everyone knows will prevent most mistakes.

What you can do:

  • Use AI to rephrase, summarize or structure text that contains no personal data and no confidential information.
  • Replace names and identifiers with neutral labels before pasting text ("Customer A," "Supplier B").
  • Work with accounts approved by the company, not personal accounts.
  • Review every answer before sending it to a customer or using it to make a decision.

What to avoid:

  • Pasting exports of customers, employees or patients, even "just to test."
  • Sending payslips, ID documents, signed contracts or health data to a consumer tool.
  • Copying WhatsApp conversations with customers without anonymizing them.
  • Sharing passwords, access credentials or banking details.
  • Turning on, without approval, an AI extension that reads your email or shared folders.

One question to ask before each use: "Would I be comfortable if someone outside the company read this text?" If the answer is no, don't paste it as is.

Consumer tools or business solutions

Both have their place. The main difference is how much control you keep.

What to checkConsumer toolBusiness offer
Training on your dataPossible, depending on settingsUsually excluded by contract
AccountsPersonal, managed by each employeeCentralized, managed by the company
Conversation retentionSet by the providerOften configurable
When an employee leavesAccess is hard to revokeAccount deactivated
Contractual frameworkStandard terms of serviceWritten commitments on data

A consumer tool works for tasks with no sensitive data: finding a title, fixing a sentence, explaining an Excel formula. As soon as customer, HR or financial data is involved, a properly configured business offer is the sensible choice.

Keep in mind that a business offer does not solve everything. If personal data is processed outside Morocco, the question of transfer abroad still needs to be reviewed under Law 09-08.

For highly sensitive data, confidentiality has to be built in from the start of the software design. That is the approach we follow for Vertus Health, our platform for mental-health professionals, whose clinical notes are end-to-end encrypted.

Setting up an AI usage policy

An AI usage policy fits in a few pages. It states what is allowed, what is not and who to ask. It usually covers:

  1. Approved tools, with the accounts to use and the settings to apply (history, training turned off when the option exists).
  2. Data categories, for example public, internal and sensitive, with what can and cannot be done with AI for each one.
  3. Prohibited uses, illustrated with examples from your own business.
  4. Human review: any AI output meant for a customer or a decision is checked by a person.
  5. A point of contact, who answers questions, approves new tools and connects the policy with your CNDP filings.
  6. What to do after a mistake: who to notify if data was shared by accident.
  7. A review date, because tools and their terms change often.

A policy only works if people understand it. Walk your team through it with real cases from your daily work, rather than sending it as an attachment.

Putting it into practice with your teams

Using AI without exposing your data is mostly a matter of habits: knowing what you paste, where, and why. The Aisobotics team helps companies with this, in Morocco and abroad: choosing tools, drafting the policy and running interactive workshops, online or on site.

Explore our AI consulting and workshops offer, then book a free discovery call to talk it through with us.

Custom software or off-the-shelf: how to choose?

Further reading

Want a workshop for your teams?

Tell us about your context on a free discovery call: we will propose a tailored program.

Book a free discovery call