Guides
Reference pages we maintain: what the law requires, what it changes in software, and how to implement it. Every guide carries its last-reviewed date.
The CNDP, in one page
The CNDP is Morocco's national commission for the protection of personal data — the authority responsible for law 09-08 on the protection of individuals with regard to the processing of personal data. In plain terms: if your company holds information about people — customers, employees, patients, members, applicants — the CNDP is the body you answer to.
These guides exist because the available information almost always stops in the same place. The regulator describes the obligation. Law firms describe filing the paperwork. Nobody describes the software — what actually has to change inside a system for compliance to be true rather than merely declared. That is the half of the subject we work on daily, and the half you will find here.
Who needs to care
Far more companies than currently do. A processing activity is not a piece of software: it is a purpose. Which means a company convinced it has no exposure often has five activities without realising:
- a customer file — quotes, invoices, history of exchanges;
- personnel administration — payroll, leave, appraisals, applications received;
- video surveillance of the premises;
- access control — badges, time clock, entry register;
- prospecting — web forms, newsletter, call lists.
Each has its own purpose, its own retention period and its own recipients. Each is therefore declared for what it is, not as one lump.
The sectors the CNDP names as enforcement priorities are healthcare providers, the pharmaceutical industry, hospitality, online retail and higher education. If you are in one of them and have filed nothing, this is the first thing to deal with.
Two regimes, and why the distinction sets your schedule
The question that shapes the whole file is not "must we declare?" but "declaration or authorisation?" The regime depends on the nature of the data and the purpose of the processing — never on the size of the company.
A declaration is a notification: you inform the CNDP before putting the processing into effect. A prior authorisation is a decision: you wait for the answer, and the processing cannot start in the meantime. Health data falls under the second regime.
On a software project that difference is not administrative, it is a delivery milestone. An authorisation filed too late moves a go-live date, and no engineering team can win that time back. It is why we handle compliance at scoping rather than at testing.
The seven guides
Each answers a question we are genuinely asked, at the level of detail that is missing elsewhere.
- CNDP declaration: who must declare, what, and how — the starting point. What a processing activity is, how to tell whether you fall under declaration or authorisation, the corresponding forms, the deadlines, and above all what a receipt does not prove.
- Health data: prior authorisation, not declaration — for clinics, laboratories, practices and coverage bodies. What "health data" actually covers, what the regime means for your schedule, and what the software has to be able to do: separate by role, log reads, enforce a retention period per category.
- Law 09-08 and the GDPR: what overlaps, what does not substitute — for companies working with Europe and for subsidiaries of European groups. Being GDPR-compliant does not make you compliant in Morocco, and the reason is structural: the prior formality.
- Consent: collecting it, proving it, honouring withdrawal — why a checkbox is not enough, when consent is the wrong legal basis, and what a system must record for a consent to be demonstrable.
- Employee data: payroll, badges, applications, video surveillance — the most universal and least declared activity of all. The retention periods that cause problems in practice, and the limits of monitoring staff.
- Which CNDP form applies, and how to file it — F211, F214, F112, F113, F115: what separates the two regimes, why F115 concerns public registers only, what to attach, and the deadline nobody mentions.
- CCTV and the CNDP — filming at work or in a place open to the public: the applicable regime, informing people, proportionality, and what an inspection actually checks.
Where to start
With the inventory, never with a form. List the purposes before anything else: what data, collected where, kept how long, accessible by whom, shared with whom. That document is what then determines the regime and the form — doing it the other way round is what makes a file come back.
If you do not know where you stand, our CNDP self-assessment gives a first bearing in eight questions: free, no sign-up, and nothing is recorded. It does not replace an audit — it tells you whether you need one.
And if the answer is yes, see CNDP compliance and sensitive data: the audit of your processing activities, the file itself, then the technical changes that make the system hold what the declaration claims.

Compliance & regulation
Video surveillance and the CNDP: what law 09-08 requires
Installing cameras is a processing of personal data. What has to be declared, what has to be displayed, and the questions that decide which regime applies.

Compliance & regulation
CNDP declaration: who must declare, what, and how
Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.

Compliance & regulation
Health data and the CNDP: prior authorisation, not declaration
Clinics, laboratories and health funds: health data falls under CNDP prior authorisation. What that changes in a project schedule and in the software.

Compliance & regulation
Law 09-08 and the GDPR: what overlaps, and what does not substitute
Being GDPR-compliant does not make you compliant in Morocco, and the reverse is also true. The differences that matter in practice: prior formality, authority, transfers.

Compliance & regulation
Consent to personal data in Morocco: collecting it, proving it, honouring withdrawal
Consent is not a checkbox: it is evidence you must keep and a withdrawal you must honour. What that means for a website, a form and a customer database.

Compliance & regulation
Employee data and the CNDP: payroll, badges, applications, video surveillance
HR management is a personal data processing activity that must be declared. What payroll, access control, cameras and received CVs cover — and what you must delete.
Newsletter
Get our new guides and their updates.

