Skip to main content
Reference guides

Guides

Reference pages we maintain: what the law requires, what it changes in software, and how to implement it. Every guide carries its last-reviewed date.

The CNDP, in one page

The CNDP is Morocco's national commission for the protection of personal data — the authority responsible for law 09-08 on the protection of individuals with regard to the processing of personal data. In plain terms: if your company holds information about people — customers, employees, patients, members, applicants — the CNDP is the body you answer to.

These guides exist because the available information almost always stops in the same place. The regulator describes the obligation. Law firms describe filing the paperwork. Nobody describes the software — what actually has to change inside a system for compliance to be true rather than merely declared. That is the half of the subject we work on daily, and the half you will find here.

Who needs to care

Far more companies than currently do. A processing activity is not a piece of software: it is a purpose. Which means a company convinced it has no exposure often has five activities without realising:

  • a customer file — quotes, invoices, history of exchanges;
  • personnel administration — payroll, leave, appraisals, applications received;
  • video surveillance of the premises;
  • access control — badges, time clock, entry register;
  • prospecting — web forms, newsletter, call lists.

Each has its own purpose, its own retention period and its own recipients. Each is therefore declared for what it is, not as one lump.

The sectors the CNDP names as enforcement priorities are healthcare providers, the pharmaceutical industry, hospitality, online retail and higher education. If you are in one of them and have filed nothing, this is the first thing to deal with.

Two regimes, and why the distinction sets your schedule

The question that shapes the whole file is not "must we declare?" but "declaration or authorisation?" The regime depends on the nature of the data and the purpose of the processing — never on the size of the company.

A declaration is a notification: you inform the CNDP before putting the processing into effect. A prior authorisation is a decision: you wait for the answer, and the processing cannot start in the meantime. Health data falls under the second regime.

On a software project that difference is not administrative, it is a delivery milestone. An authorisation filed too late moves a go-live date, and no engineering team can win that time back. It is why we handle compliance at scoping rather than at testing.

The seven guides

Each answers a question we are genuinely asked, at the level of detail that is missing elsewhere.

Where to start

With the inventory, never with a form. List the purposes before anything else: what data, collected where, kept how long, accessible by whom, shared with whom. That document is what then determines the regime and the form — doing it the other way round is what makes a file come back.

If you do not know where you stand, our CNDP self-assessment gives a first bearing in eight questions: free, no sign-up, and nothing is recorded. It does not replace an audit — it tells you whether you need one.

And if the answer is yes, see CNDP compliance and sensitive data: the audit of your processing activities, the file itself, then the technical changes that make the system hold what the declaration claims.

Video surveillance and the CNDP: what law 09-08 requires

Compliance & regulation

Video surveillance and the CNDP: what law 09-08 requires

Installing cameras is a processing of personal data. What has to be declared, what has to be displayed, and the questions that decide which regime applies.

5 min read
CNDP declaration: who must declare, what, and how

Compliance & regulation

CNDP declaration: who must declare, what, and how

Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.

3 min read
Health data and the CNDP: prior authorisation, not declaration

Compliance & regulation

Health data and the CNDP: prior authorisation, not declaration

Clinics, laboratories and health funds: health data falls under CNDP prior authorisation. What that changes in a project schedule and in the software.

3 min read
Law 09-08 and the GDPR: what overlaps, and what does not substitute

Compliance & regulation

Law 09-08 and the GDPR: what overlaps, and what does not substitute

Being GDPR-compliant does not make you compliant in Morocco, and the reverse is also true. The differences that matter in practice: prior formality, authority, transfers.

3 min read
Consent to personal data in Morocco: collecting it, proving it, honouring withdrawal

Compliance & regulation

Consent to personal data in Morocco: collecting it, proving it, honouring withdrawal

Consent is not a checkbox: it is evidence you must keep and a withdrawal you must honour. What that means for a website, a form and a customer database.

2 min read
Employee data and the CNDP: payroll, badges, applications, video surveillance

Compliance & regulation

Employee data and the CNDP: payroll, badges, applications, video surveillance

HR management is a personal data processing activity that must be declared. What payroll, access control, cameras and received CVs cover — and what you must delete.

3 min read

Newsletter

Get our new guides and their updates.

Chat on WhatsApp