Skip to main content
Self-assessment

Where do you actually stand with the CNDP?

Eight questions, two minutes. You get the points worth verifying under law 09-08 — and a sense of your personal exposure as a director.

No answer is transmitted or stored: the calculation runs in your browser. No e-mail address requested.

Answered 0/8

Do you know precisely what personal data your company keeps?
1

Do you know precisely what personal data your company keeps?

Clients, patients, members, employees, applicants — including in spreadsheets and mailboxes.

Do you process health, biometric or judicial data?
2

Do you process health, biometric or judicial data?

Patient records, test results, sick leave, pre-authorisation files.

Has your processing been declared to the CNDP?
3

Has your processing been declared to the CNDP?

The law expects a declaration before processing begins, not after.

Are people informed at the point of collection?
4

Are people informed at the point of collection?

A clear notice on the form, contract or admission document: who collects, why, and what rights apply.

Does each user of your system access only the data their role requires?
5

Does each user of your system access only the data their role requires?

An admin account shared by several people, or full access granted by default, means “no”.

Can you tell who opened a given record, and when?
6

Can you tell who opened a given record, and when?

A consultable access log, not just backups.

Are retention periods defined and actually enforced?
7

Are retention periods defined and actually enforced?

Defined on paper is not enough: something has to actually purge.

Do you know which external providers access this data?
8

Do you know which external providers access this data?

Hosting provider, software vendor, maintenance supplier, e-mail service.

Why this is surfacing now

Morocco’s data-protection authority has stepped up enforcement, and the sectors it names as priorities include healthcare providers, pharmaceuticals, hospitality, e-commerce and higher education. What those sectors share: a lot of personal — often sensitive — data, in systems assembled over years.

The part discovered late is personal exposure. For sensitive data, law 09-08 provides for financial penalties and liability that can reach the director, with imprisonment possible in the most serious cases. That is what separates this from an ordinary IT project.

Chat on WhatsApp