Employee data and the CNDP: payroll, badges, applications, video surveillance
HR management is a personal data processing activity that must be declared. What payroll, access control, cameras and received CVs cover — and what you must delete.
Human resources management is one of the most universal and least declared processing activities. Every company with employees processes their personal data; many also process the data of candidates who will never work there, and video surveillance footage that films both.
The HR activities to distinguish
These are different purposes, therefore different activities — with distinct retention periods and recipients:
- Payroll and personnel administration — contracts, payslips, leave, absences.
- Recruitment — CVs, cover letters, interview notes, including unsolicited applications.
- Access control and time recording — badges, time clock, register.
- Video surveillance of the premises, which films employees at work.
- Appraisal and career — objectives, annual reviews, training plans.
- Digital tools — connection logs, business email, remote access.
The recurring question: how long do you keep it?
The rule is easy to state and rarely applied: as long as the purpose justifies, plus any period imposed by a legal obligation — and not a day more "just in case".
The two cases that cause problems in practice:
- Unsuccessful applications. Almost every company keeps them indefinitely, in a mailbox or a shared folder. That is a store of personal data with no active purpose and uncontrolled access. It needs a period, and a deletion that runs.
- Video surveillance. Footage has a short period, and the control point is who can view it and whether those viewings are traced — not only how long it is kept.
The limits of monitoring an employee
An HR activity cannot become general surveillance. Three principles handle most situations: proportionality (a camera over a workstation is hard to justify; one at a warehouse entrance far less so), prior information of the people concerned, and a determined purpose — a system installed for security does not then measure productivity.
Consent is a fragile basis here: the employment relationship makes it difficult to treat agreement as genuinely free. See the guide on consent.
HR sub-processors
An outsourced payroll firm, an HR software vendor, a recruitment platform, a remote monitoring provider: all process data on your behalf, and you remain responsible. You need a written commitment, knowledge of where the data is hosted, and a prohibition on onward sub-processing without agreement.
What a control asks for on the HR side
The list of HR activities and their legal basis, the declaration receipt, the retention periods as enforced (applications included), the notice given to employees, the access matrix for personnel files, and the viewing logs for footage. Our job is to make that list producible by the system: see CNDP compliance and sensitive data.
Related guides: the CNDP declaration, law 09-08 and the GDPR.
Related articles

Compliance & regulation
CNDP forms: which one applies to your processing
F211, F214, F112, F113, F115: five forms, two regimes, and a choice that follows from your processing inventory — not from your preference.

Compliance & regulation
Video surveillance and the CNDP: what law 09-08 requires
Installing cameras is a processing of personal data. What has to be declared, what has to be displayed, and the questions that decide which regime applies.

Compliance & regulation
CNDP declaration: who must declare, what, and how
Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.
Newsletter
Get our upcoming articles straight to your inbox.

