Skip to main content
Compliance & regulation

CNDP forms: which one applies to your processing

F211, F214, F112, F113, F115: five forms, two regimes, and a choice that follows from your processing inventory — not from your preference.

Digi4·· Last reviewed: ·6 min read

The CNDP does not publish a single form. It publishes several, and picking the wrong one does not end in a refusal: the file comes back, and the time lost is project time. This guide says which one applies, what separates them, and in what order to go about it.

Two regimes before five forms

Everything starts with one question: does your processing fall under declaration or under prior authorisation?

  • Declaration is the ordinary regime. You declare, the CNDP acknowledges receipt, and you can start.
  • Prior authorisation covers the most sensitive processing — health data first among them. Here, nothing starts before the decision.

The form follows from the regime, and the regime follows from the nature of the data and the purpose. Which is why the form is the last thing to choose, not the first.

The five forms

FormRegimeUse
F211DeclarationNormal prior declaration of a processing activity
F214DeclarationSimplified prior declaration
F112AuthorisationPrior-authorisation request — normal
F113AuthorisationPrior-authorisation request — simplified
F115Special caseDeclaration of the controller of a public register

Special case: F115 is not a third general-purpose route. It declares the identity of the controller of a public register. If your processing is not a public register, it is not your form — and that is the most frequent error we find on files we take over.

Normal or simplified: what actually differs

The simplified versions — F214 for a declaration, F113 for an authorisation — exist for common, standardised processing: the kind whose purpose and data categories match a framework the CNDP has already described. The normal version is the general case: as soon as your processing departs from the model, it is F211 or F112.

The useful reflex: you do not pick the simplified form to go faster. You pick it because the processing genuinely fits the simplified framework. Filing an F214 for a processing activity that does not fit costs more time than the F211 would have.

What to attach

The form is only the cover of the file. What actually takes preparation is what it declares:

  • The purpose of each processing activity, stated precisely. "Customer management" is not a purpose; "invoicing and debt recovery" is.
  • The categories of data and the people concerned.
  • The recipients, including sub-processors and hosting providers.
  • The retention period per category — and it must be the one the system actually enforces.
  • The security measures: access partitioning, logging, encryption.
  • Any transfers outside Morocco, with their destination.

The deadlines, and the one nobody mentions

  • 24 hours — the period within which the CNDP issues the receipt for the declaration. It is an acknowledgement, not a decision: a receipt does not attest that the processing is compliant.
  • 8 days — the window in which the CNDP may notify you that it is moving your processing to the prior-authorisation regime, if it judges that the activity presents manifest risks to privacy. It is a power the Commission holds, not a deadline imposed on you.
  • 2 months, extendable once only — the period within which the CNDP gives and notifies its decision on an authorisation request. Plan it as a project milestone: four months in the worst case.

The decisive point, and the one most often left out: if the file is incomplete, none of these periods start running until the CNDP has received the information or documents it asked for. Filing quickly but incompletely gains nothing at all — which is why the inventory happens before the filing, not during it.

What order to go about it

  1. Inventory the processing activities. One activity per purpose, not one per piece of software.
  2. Qualify each one: declaration or authorisation, according to the data and the purpose.
  3. Choose the form — it follows from the two previous steps.
  4. Assemble the documents, and check that what you declare is what the system does.
  5. File, and treat an authorisation decision as a scheduling milestone.

Step 2 is covered in detail in the guide on the CNDP declaration: who must declare, what, and how. For health data processing, see health data and the CNDP. If you are coming from the GDPR, what recycles and what does not.

Need the file and the software to say the same thing? That is exactly our work: CNDP compliance.

Newsletter

Get our upcoming articles straight to your inbox.

Chat on WhatsApp