Use this skill when a user asks to audit, check, or assess the legal compliance of a Moroccan e-commerce website, specifically regarding:
Out of scope: Meta/Google advertising compliance (covered by a separate skill), law of other countries, definitive legal advice, marketplaces/multi-vendor platforms (not yet covered by this methodology), informal commerce without a website (selling only through a Facebook/Instagram page + WhatsApp, without formalized Terms & Conditions or privacy policy — not covered here, as this methodology assumes the existence of a website). The results of this audit are a structured starting point, to be validated by a professional before any contentious action.
The audit always follows the same order, from the most visible/quick-to-check items to the more
specific ones. For each site audited, duplicate assets/grille-audit-site-web.xlsx and fill in
the Status column (Compliant / Non-compliant / To correct / To verify) as you go.
The information needed for the audit is not all in one place — do not limit the check to the footer. Browse the entire site: homepage, footer, menu/sidebar, and a selection of product pages, to gather the elements required by each item in the grid. If an element remains unclear or cannot be found after this review (e.g. CNDP number never displayed, ambiguous return procedure), flag it as "To verify with the client" rather than guessing or defaulting to non-compliant.
Some elements are non-negotiable (e.g. right of withdrawal, seller identity, consent for data collection): their absence should always be treated as High priority, regardless of context. Others tolerate some flexibility depending on the client's context (e.g. intellectual property terms of use, Low priority) — the priority already indicated in the grid reflects this distinction.
First check whether the site has a Privacy Policy and Terms & Conditions (often in the footer). Their mere presence is not enough: verify that they are genuinely tailored to the site (not an irrelevant generic copy-paste) and that they cover, point by point:
Privacy Policy (Law 09-08) — check each of these points separately:
Terms & Conditions (Law 31-08) — check each of these points separately, not as a single block:
Once the foundational documents have been checked, verify the consistency of the information shown on product pages themselves: price, delivery times, availability — this information should match what the Terms & Conditions state.
Check separately:
Check whether the type of product sold requires a specific authorization — only relevant if the client sells in a concerned sector:
Check for the presence of a CNDP declaration receipt number (mandatory as soon as personal data is collected). Medium-term priority (official process), useful for long-term recommendations, even though it does not block day-to-day sales.
Check for a functional consent banner before advertising trackers are activated (Meta Pixel, Google Analytics) — in accordance with Art. 4 of Law 09-08.
Check separately:
Check that the legal withdrawal period (7 clear days from receipt, extended to 30 days if the mandatory information was not confirmed in writing) is clearly stated, along with its procedure and exceptions (personalized products, perishable goods, unsealed software, services already started).
The level of expectation depends on the size of the site:
If an element cannot be confirmed from outside the site (e.g. actual existence of a CNDP declaration, exact content of a supplier contract), flag it as "To verify with the client" rather than defaulting it to Compliant or Non-compliant.
assets/grille-audit-site-web.xlsx duplicated and filled in) — status per
item, with the legal reference already indicated in the grid.assets/CGV_Template_Maroc_V3.docx and assets/Politique_Confidentialite_Maroc_V2.docx as a
starting point — adapt the bracketed placeholders ([Company name], [RC number], etc.) to
the audited client rather than copying them as-is.assets/grille-audit-site-web.xlsx — 14-item Website audit grid, with legal reference and
priority level for each item.assets/CGV_Template_Maroc_V3.docx — Terms & Conditions template compliant with Law 31-08,
with fields to customize (in brackets).assets/Politique_Confidentialite_Maroc_V2.docx — Privacy Policy template compliant with Law
09-08, with a reminder of the prior CNDP declaration obligation.