Skip to main content
Compliance & regulation

CNDP declaration: who must declare, what, and how

Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.

Digi4·· Last reviewed: ·3 min read

If your company holds a customer file, runs payroll, films its premises or collects addresses through a web form, it processes personal data — and law 09-08 requires that you declare it to the CNDP before starting. This guide explains what that actually covers, how to tell whether you fall under declaration or authorisation, and what compliance demands of the software.

What a "processing activity" is

This is the part that surprises people most: a processing activity is not a piece of software, it is a purpose. The same spreadsheet can constitute two activities if it serves two ends. Conversely, five tools serving the same purpose are often a single activity.

The activities we find in almost every company:

  • Customer management — customer file, quotes, invoicing, history of exchanges.
  • Personnel administration — contracts, payslips, leave, appraisals, applications received.
  • Video surveillance of the premises.
  • Access control — badges, time clock, entry register.
  • Prospecting — web forms, newsletter, call lists.

Five activities for a company that thought it had none. Each has a different purpose, retention period and set of recipients, so each is declared for what it is.

Declaration or prior authorisation?

The question that determines the whole schedule. The regime depends on the nature of the data and the purpose, never on the size of the company.

  • Declaration — the ordinary regime. You notify the activity before putting it into effect.
  • Prior authorisation — for the most sensitive activities: foremost health data, along with certain transfers outside Morocco and certain interconnections of files. Here you do not notify: you wait for a decision.

The difference is practical before it is legal. Processing subject to authorisation cannot start because the file has been submitted — which on a software project has to enter the delivery plan at scoping. See our dedicated guide on health data.

The forms

  • F211 — standard prior declaration of a processing activity.
  • F214 — simplified prior declaration.
  • F112 — application for prior authorisation, standard.
  • F113 — application for prior authorisation, simplified.

Special case: F115 is not a third route. It declares the identity of the controller of a public register.

The choice follows from the inventory, not the other way round. A file submitted under the wrong regime comes back, and the time lost is project time.

The deadlines

  • 24 hours — issue of the receipt for a declaration: an acknowledgement, not a decision.
  • 8 days — the window in which the CNDP may notify you that it is moving the activity to the prior-authorisation regime, if it judges the risks to privacy manifest.
  • Two months, extendable once only — the CNDP's decision on an authorisation request.

And the point that changes everything: if the file is incomplete, none of these periods run until the CNDP has received the documents it asked for.

CNDP authorisation: when it is mandatory

The question comes up in this form — "do I need a CNDP authorisation?" — and the answer does not depend on the size of the company but on the nature of the data and the purpose. Prior authorisation is the regime for the most sensitive processing, health data first among them. The form is F112 (or F113 for its simplified version), and not F211, which is the declaration.

Three practical consequences, and all of them are about scheduling:

  • Nothing starts before the decision. A filed request authorises nothing. That is the fundamental difference from a declaration, where the receipt lets you begin.
  • Two months, extendable once only. Plan for up to four, and treat it as a project milestone rather than an administrative formality.
  • An incomplete file starts no clock. The counter only begins when the requested documents arrive, so filing early but incomplete gains nothing whatsoever.

There is also a route you do not choose: within 8 days of a declaration, the CNDP may notify you that it is moving your processing to the authorisation regime, if it judges that the activity presents manifest risks to privacy. A project whose schedule assumes a simple declaration therefore has to be able to absorb that move — which is why we qualify the regime at scoping and not at acceptance testing. Choosing the form itself is covered in detail in which CNDP form applies.

What a declaration does not settle

A receipt is not compliance. It attests that you declared; it does not attest that your system does what the declaration says. That is exactly what a control checks:

  • Is the declared retention period actually enforced? A written policy deletes nothing: you need a purge that runs.
  • Are access rights separated as declared, or does everyone see everything?
  • Are reads of sensitive data logged?
  • Can you export and delete a person’s data on request — including from backups, after their own cycle?
  • Are your sub-processors covered in writing, and do you know where the data sits?

That is the half of the work a legal opinion cannot do, and the half we do: see CNDP compliance and sensitive data.

Where to start

With the inventory, always. List the purposes before filling in a form: what data, collected where, kept how long, accessible by whom, shared with whom. Our CNDP self-assessment gives a first bearing in eight questions — free, no sign-up, and nothing is recorded.

Related guides: law 09-08 and the GDPR, consent, employee data.

Newsletter

Get our upcoming articles straight to your inbox.

Chat on WhatsApp