CNDP declaration: who must declare, what, and how
Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.
If your company holds a customer file, runs payroll, films its premises or collects addresses through a web form, it processes personal data — and law 09-08 requires that you declare it to the CNDP before starting. This guide explains what that actually covers, how to tell whether you fall under declaration or authorisation, and what compliance demands of the software.
What a "processing activity" is
This is the part that surprises people most: a processing activity is not a piece of software, it is a purpose. The same spreadsheet can constitute two activities if it serves two ends. Conversely, five tools serving the same purpose are often a single activity.
The activities we find in almost every company:
- Customer management — customer file, quotes, invoicing, history of exchanges.
- Personnel administration — contracts, payslips, leave, appraisals, applications received.
- Video surveillance of the premises.
- Access control — badges, time clock, entry register.
- Prospecting — web forms, newsletter, call lists.
Five activities for a company that thought it had none. Each has a different purpose, retention period and set of recipients, so each is declared for what it is.
Declaration or prior authorisation?
The question that determines the whole schedule. The regime depends on the nature of the data and the purpose, never on the size of the company.
- Declaration — the ordinary regime. You notify the activity before putting it into effect.
- Prior authorisation — for the most sensitive activities: foremost health data, along with certain transfers outside Morocco and certain interconnections of files. Here you do not notify: you wait for a decision.
The difference is practical before it is legal. Processing subject to authorisation cannot start because the file has been submitted — which on a software project has to enter the delivery plan at scoping. See our dedicated guide on health data.
The forms
- F211 — declaration of a personal data processing activity.
- F115 — application for prior authorisation.
- F112 — amendment or reclassification of an already notified activity.
The choice follows from the inventory, not the other way round. A file submitted under the wrong regime comes back, and the time lost is project time.
The deadlines
- 24 hours — acknowledgement of receipt of a submission.
- Two months — review of an authorisation request, extendable once. Plan for four months in the worst case.
- 8 days — the deadline applicable to a reclassification.
What a declaration does not settle
A receipt is not compliance. It attests that you declared; it does not attest that your system does what the declaration says. That is exactly what a control checks:
- Is the declared retention period actually enforced? A written policy deletes nothing: you need a purge that runs.
- Are access rights separated as declared, or does everyone see everything?
- Are reads of sensitive data logged?
- Can you export and delete a person’s data on request — including from backups, after their own cycle?
- Are your sub-processors covered in writing, and do you know where the data sits?
That is the half of the work a legal opinion cannot do, and the half we do: see CNDP compliance and sensitive data.
Where to start
With the inventory, always. List the purposes before filling in a form: what data, collected where, kept how long, accessible by whom, shared with whom. Our CNDP self-assessment gives a first bearing in eight questions — free, no sign-up, and nothing is recorded.
Related guides: law 09-08 and the GDPR, consent, employee data.
Related articles

Compliance & regulation
Health data and the CNDP: prior authorisation, not declaration
Clinics, laboratories and health funds: health data falls under CNDP prior authorisation. What that changes in a project schedule and in the software.

Compliance & regulation
Law 09-08 and the GDPR: what overlaps, and what does not substitute
Being GDPR-compliant does not make you compliant in Morocco, and the reverse is also true. The differences that matter in practice: prior formality, authority, transfers.

Compliance & regulation
Consent to personal data in Morocco: collecting it, proving it, honouring withdrawal
Consent is not a checkbox: it is evidence you must keep and a withdrawal you must honour. What that means for a website, a form and a customer database.
Newsletter
Get our upcoming articles straight to your inbox.

