Skip to main content
Compliance & regulation

CNDP compliance: what a Moroccan company actually has to do

Morocco's data-protection authority has stepped up enforcement and explicitly names healthcare, pharmaceuticals, hospitality, e-commerce and higher education. Here are the concrete obligations — and the director's personal exposure.

Digi4·August 4, 2026·7 min read

What this is about

Moroccan law 09-08 governs the processing of personal data. It applies as soon as you keep information about identifiable people: clients, patients, members, employees, applicants. Which means: almost every company.

The prior declaration

The law's principle is a declaration before processing begins. Many companies have processed data for years without ever declaring — often without knowing it was required. Processing of sensitive data, health data included, falls under a stricter regime than simple declaration.

What the authority looks at first

The sectors named as priorities in its enforcement include healthcare providers, pharmaceuticals, hospitality, e-commerce and higher education. The common thread: high volumes of personal — often sensitive — data, in systems assembled over time.

The director's exposure

This is the part discovered late. Penalties are not only institutional: for sensitive data the law provides for fines and liability that can reach the director personally, with imprisonment possible in the most serious cases. This is not a topic to delegate entirely to an IT supplier.

Six things to put in place

  1. Map it — what data, collected where, kept how long, accessible by whom, sent to whom.
  2. Declare it — the file matching your real processing, not the processing you assume you have.
  3. Inform people — a clear notice at collection, with a purpose they can understand.
  4. Manage access rights — each user sees only what their role requires. One admin account shared by five people is not access management.
  5. Log it — know who opened which record and when. That is what an inspection asks for.
  6. Purge it — a defined retention period, and a mechanism that actually enforces it.

Why this happens in the software

A legal opinion describes what ought to be true. Compliance happens in the application: who can open which record, what gets logged, what happens when retention expires. If your system cannot answer those questions, no written procedure will compensate.

We do both halves — the analysis and the change to the system. See our CNDP compliance service.

Newsletter

Get our upcoming articles straight to your inbox.

Chat on WhatsApp