CNDP compliance: what a Moroccan company actually has to do
Morocco's data-protection authority has stepped up enforcement and explicitly names healthcare, pharmaceuticals, hospitality, e-commerce and higher education. Here are the concrete obligations — and the director's personal exposure.
What this is about
Moroccan law 09-08 governs the processing of personal data. It applies as soon as you keep information about identifiable people: clients, patients, members, employees, applicants. Which means: almost every company.
The prior declaration
The law's principle is a declaration before processing begins. Many companies have processed data for years without ever declaring — often without knowing it was required. Processing of sensitive data, health data included, falls under a stricter regime than simple declaration.
What the authority looks at first
The sectors named as priorities in its enforcement include healthcare providers, pharmaceuticals, hospitality, e-commerce and higher education. The common thread: high volumes of personal — often sensitive — data, in systems assembled over time.
The director's exposure
This is the part discovered late. Penalties are not only institutional: for sensitive data the law provides for fines and liability that can reach the director personally, with imprisonment possible in the most serious cases. This is not a topic to delegate entirely to an IT supplier.
Six things to put in place
- Map it — what data, collected where, kept how long, accessible by whom, sent to whom.
- Declare it — the file matching your real processing, not the processing you assume you have.
- Inform people — a clear notice at collection, with a purpose they can understand.
- Manage access rights — each user sees only what their role requires. One admin account shared by five people is not access management.
- Log it — know who opened which record and when. That is what an inspection asks for.
- Purge it — a defined retention period, and a mechanism that actually enforces it.
Why this happens in the software
A legal opinion describes what ought to be true. Compliance happens in the application: who can open which record, what gets logged, what happens when retention expires. If your system cannot answer those questions, no written procedure will compensate.
We do both halves — the analysis and the change to the system. See our CNDP compliance service.
Related articles

Compliance & regulation
Electronic care claims: what changes for clinics and laboratories
Electronic submission is becoming the norm for doctors, pharmacists and laboratories. The important detail: it can happen through the insurer's portal, or through your own software.

Compliance & regulation
Property-manager accounting: what the new Moroccan framework requires
A decree published in the official bulletin requires standardised accounting from condominium managers, with obligations that increase according to the level of charges managed.
Compliance & regulation
Getting a digitalisation project co-funded: how it actually works
Several Moroccan public schemes co-fund digital transformation for small and medium companies. Here is the mechanism, the usual conditions, and the mistakes that waste a cycle.
Newsletter
Get our upcoming articles straight to your inbox.

