CNDP forms: which one applies to your processing
F211, F214, F112, F113, F115: five forms, two regimes, and a choice that follows from your processing inventory — not from your preference.
The CNDP does not publish a single form. It publishes several, and picking the wrong one does not end in a refusal: the file comes back, and the time lost is project time. This guide says which one applies, what separates them, and in what order to go about it.
Two regimes before five forms
Everything starts with one question: does your processing fall under declaration or under prior authorisation?
- Declaration is the ordinary regime. You declare, the CNDP acknowledges receipt, and you can start.
- Prior authorisation covers the most sensitive processing — health data first among them. Here, nothing starts before the decision.
The form follows from the regime, and the regime follows from the nature of the data and the purpose. Which is why the form is the last thing to choose, not the first.
The five forms
| Form | Regime | Use |
|---|---|---|
| F211 | Declaration | Normal prior declaration of a processing activity |
| F214 | Declaration | Simplified prior declaration |
| F112 | Authorisation | Prior-authorisation request — normal |
| F113 | Authorisation | Prior-authorisation request — simplified |
| F115 | Special case | Declaration of the controller of a public register |
Special case: F115 is not a third general-purpose route. It declares the identity of the controller of a public register. If your processing is not a public register, it is not your form — and that is the most frequent error we find on files we take over.
Normal or simplified: what actually differs
The simplified versions — F214 for a declaration, F113 for an authorisation — exist for common, standardised processing: the kind whose purpose and data categories match a framework the CNDP has already described. The normal version is the general case: as soon as your processing departs from the model, it is F211 or F112.
The useful reflex: you do not pick the simplified form to go faster. You pick it because the processing genuinely fits the simplified framework. Filing an F214 for a processing activity that does not fit costs more time than the F211 would have.
What to attach
The form is only the cover of the file. What actually takes preparation is what it declares:
- The purpose of each processing activity, stated precisely. "Customer management" is not a purpose; "invoicing and debt recovery" is.
- The categories of data and the people concerned.
- The recipients, including sub-processors and hosting providers.
- The retention period per category — and it must be the one the system actually enforces.
- The security measures: access partitioning, logging, encryption.
- Any transfers outside Morocco, with their destination.
The deadlines, and the one nobody mentions
- 24 hours — the period within which the CNDP issues the receipt for the declaration. It is an acknowledgement, not a decision: a receipt does not attest that the processing is compliant.
- 8 days — the window in which the CNDP may notify you that it is moving your processing to the prior-authorisation regime, if it judges that the activity presents manifest risks to privacy. It is a power the Commission holds, not a deadline imposed on you.
- 2 months, extendable once only — the period within which the CNDP gives and notifies its decision on an authorisation request. Plan it as a project milestone: four months in the worst case.
The decisive point, and the one most often left out: if the file is incomplete, none of these periods start running until the CNDP has received the information or documents it asked for. Filing quickly but incompletely gains nothing at all — which is why the inventory happens before the filing, not during it.
What order to go about it
- Inventory the processing activities. One activity per purpose, not one per piece of software.
- Qualify each one: declaration or authorisation, according to the data and the purpose.
- Choose the form — it follows from the two previous steps.
- Assemble the documents, and check that what you declare is what the system does.
- File, and treat an authorisation decision as a scheduling milestone.
Step 2 is covered in detail in the guide on the CNDP declaration: who must declare, what, and how. For health data processing, see health data and the CNDP. If you are coming from the GDPR, what recycles and what does not.
Need the file and the software to say the same thing? That is exactly our work: CNDP compliance.
Related articles
Compliance & regulation
Video surveillance and the CNDP: what law 09-08 requires
Installing cameras is a processing of personal data. What has to be declared, what has to be displayed, and the questions that decide which regime applies.

Compliance & regulation
CNDP declaration: who must declare, what, and how
Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.

Compliance & regulation
Health data and the CNDP: prior authorisation, not declaration
Clinics, laboratories and health funds: health data falls under CNDP prior authorisation. What that changes in a project schedule and in the software.
Newsletter
Get our upcoming articles straight to your inbox.
