lawve-ai/morocco-ecommerce-compliance-audit-omar-laftouh
Performs a legal compliance audit for a Moroccan e-commerce website, focused on personal data protection (Law 09-08) and consumer contract disclosures/obligations (Law 31-08). Use this skill when a user asks to audit, check, or assess the legal compliance of an e-commerce website operating in Morocco — presence and validity of Terms & Conditions, privacy policy, CNDP declaration, mandatory disclosures, right of withdrawal, consent banner. Out of scope: compliance for other countries, Meta/Google advertising compliance (covered by another skill), definitive legal advice (results are a starting point for professional review, not legal advice).
npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill morocco-ecommerce-compliance-audit-omar-laftouh
Use this skill when a user asks to audit, check, or assess the legal compliance of a Moroccan
e-commerce website, specifically regarding:
Out of scope: Meta/Google advertising compliance (covered by a separate skill), law of other
countries, definitive legal advice, marketplaces/multi-vendor platforms (not yet covered by this
methodology), informal commerce without a website (selling only through a Facebook/Instagram
page + WhatsApp, without formalized Terms & Conditions or privacy policy — not covered here, as
this methodology assumes the existence of a website). The results of this audit are a structured
starting point, to be validated by a professional before any contentious action.
The audit always follows the same order, from the most visible/quick-to-check items to the more
specific ones. For each site audited, duplicate assets/grille-audit-site-web.xlsx and fill in
the Status column (Compliant / Non-compliant / To correct / To verify) as you go.
The information needed for the audit is not all in one place — do not limit the check to the
footer. Browse the entire site: homepage, footer, menu/sidebar, and a selection of product pages,
to gather the elements required by each item in the grid. If an element remains unclear or cannot
be found after this review (e.g. CNDP number never displayed, ambiguous return procedure), flag
it as "To verify with the client" rather than guessing or defaulting to non-compliant.
correct 7-day period).
withdrawal anywhere on the site).
mentioned but with a 3-day period instead of 7) — in this case, specify what needs to change,
not just flag the issue.
Some elements are non-negotiable (e.g. right of withdrawal, seller identity, consent for data
collection): their absence should always be treated as High priority, regardless of context.
Others tolerate some flexibility depending on the client's context (e.g. intellectual property
terms of use, Low priority) — the priority already indicated in the grid reflects this
distinction.
First check whether the site has a Privacy Policy and Terms & Conditions (often in the
footer). Their mere presence is not enough: verify that they are genuinely tailored to the site
(not an irrelevant generic copy-paste) and that they cover, point by point:
Privacy Policy (Law 09-08) — check each of these points separately:
(marketing follow-up, resale to a third party)?
trackers are activated)
abroad
Terms & Conditions (Law 31-08) — check each of these points separately, not as a single block:
specified (who bears them), exceptions listed (personalized products, perishable goods,
unsealed software, services already started)
adaptation)
Once the foundational documents have been checked, verify the consistency of the information
shown on product pages themselves: price, delivery times, availability — this information should
match what the Terms & Conditions state.
Check separately:
informal)
general sales contact)
Check whether the type of product sold requires a specific authorization — only relevant if the
client sells in a concerned sector:
seizure, criminal prosecution, customs seizure)
as absolute top priority if detected, regardless of the rest of the audit
Check for the presence of a CNDP declaration receipt number (mandatory as soon as personal
data is collected). Medium-term priority (official process), useful for long-term
recommendations, even though it does not block day-to-day sales.
Check for a functional consent banner before advertising trackers are activated (Meta Pixel,
Google Analytics) — in accordance with Art. 4 of Law 09-08.
Check separately:
withdrawal period to 30 days)?
Check that the legal withdrawal period (7 clear days from receipt, extended to 30 days if the
mandatory information was not confirmed in writing) is clearly stated, along with its procedure
and exceptions (personalized products, perishable goods, unsealed software, services already
started).
The level of expectation depends on the size of the site:
complaint procedure, possibly mediation).
sufficient (visible email or phone number) — no formal mechanism required.
If an element cannot be confirmed from outside the site (e.g. actual existence of a CNDP
declaration, exact content of a supplier contract), flag it as "To verify with the client" rather
than defaulting it to Compliant or Non-compliant.
assets/grille-audit-site-web.xlsx duplicated and filled in) — status peritem, with the legal reference already indicated in the grid.
indicated in the grid), not just a flat list.
Privacy Policy, propose a replacement clause based on
assets/CGV_Template_Maroc_V3.docx and assets/Politique_Confidentialite_Maroc_V2.docx as a
starting point — adapt the bracketed placeholders ([Company name], [RC number], etc.) to
the audited client rather than copying them as-is.
assets/grille-audit-site-web.xlsx — 14-item Website audit grid, with legal reference andpriority level for each item.
assets/CGV_Template_Maroc_V3.docx — Terms & Conditions template compliant with Law 31-08,with fields to customize (in brackets).
assets/Politique_Confidentialite_Maroc_V2.docx — Privacy Policy template compliant with Law09-08, with a reminder of the prior CNDP declaration obligation.
Take lawve-ai/morocco-ecommerce-compliance-audit-omar-laftouh from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.