Health data and the CNDP: prior authorisation, not declaration
Clinics, laboratories and health funds: health data falls under CNDP prior authorisation. What that changes in a project schedule and in the software.
Health data is the most protected category under law 09-08. For a clinic, a laboratory, a practice or a health coverage body, that means a regime of prior authorisation from the CNDP — not a simple declaration. The difference is not administrative: it decides the date your platform can go into production.
Authorisation, and what it means for the timeline
- Review in two months, extendable once: plan for up to four.
- No start before the decision. A submitted file authorises nothing.
- The form is F112 — prior-authorisation request, normal (F113 for the simplified version). It is not F211, which is the declaration, nor F115, which is reserved for public registers.
The consequence for a software project: the file is prepared during scoping, not during testing. A healthcare platform that discovers prior authorisation three weeks before delivery has a scheduling problem nobody can solve.
What "health data" actually covers
Wider than the medical record: anything revealing a state of health, even indirectly. An appointment reason, a billed procedure, a pre-authorisation, a sick note, a test result, a prescription — and sometimes simply being attached to a care service.
That is why a health fund platform is as concerned as clinic software: reimbursing a procedure is health data. See insurance and health funds.
What the software has to be able to do
- Separate by role. Practitioner, front desk, administrator and billing do not need the same fields. "Everyone sees everything" is the most common default and the hardest to defend in a control.
- Log reads, not just changes. On a health record, knowing who looked at what is the core of traceability.
- Enforce a retention period per category — a test result, an accounting document and a prospecting record do not live the same length of time.
- Answer an access or deletion request without manual reconstruction.
- Encrypt at rest and in transit, and know where the data is hosted.
What directors discover late
For sensitive data the law provides for financial penalties and a liability that can reach the director personally. This is not a subject to delegate to a provider after the fact, and a compliance report resting on a system that cannot log access protects nobody.
Hosting or transferring data outside Morocco
Placing Moroccan data with a provider established abroad — a cloud host, a SaaS vendor, a backup provider, a support centre — constitutes a transfer of data abroad. A transfer is subject to its own regime: it is not prohibited, but it has to be identified, declared and justified in the file, and it is not settled by ticking a box.
What the CNDP wants to see on a transfer:
- The real destination. Not "the cloud", but the country where the data is stored and the countries it can be accessed from. A European hosting region with technical support on another continent means two destinations, not one.
- The purpose of the transfer. Hosting, backup, processing, support: these are not the same accesses nor the same retention periods.
- The level of protection provided at the destination, and what establishes it — the provider's contractual commitments, technical measures, access partitioning.
- Onward sub-processors. A provider who uses others lengthens the chain, and the whole chain is part of what you declare.
Two expensive mistakes, and we see them in this order. The first is discovering the transfer after filing: completing the file restarts the clock from the arrival of the missing documents, and if the transfer moves the processing into prior authorisation, it is re-filed under that regime. The second is assuming that a GDPR-compliant provider is thereby compliant in Morocco: a transfer outside Morocco is assessed under law 09-08, not under European mechanisms — the comparison is set out in law 09-08 and the GDPR.
The rule of conduct is simple: the data-flow map is drawn at scoping, hosting included, because that is the point at which changing region or provider costs a decision rather than a migration.
What about hosting abroad?
Hosting health data with a provider outside Morocco constitutes a transfer, subject to its own regime, and it must appear in the file. It is not prohibited; it has to be declared and justified. Discovering it after submission means completing the file, and the clock only restarts once the CNDP has received the missing documents. If the transfer moves the processing into the prior-authorisation regime, it is re-filed under that regime.
Related guides: the CNDP declaration, consent. Our offer: healthcare platforms and CNDP compliance.
Related articles

Compliance & regulation
CNDP forms: which one applies to your processing
F211, F214, F112, F113, F115: five forms, two regimes, and a choice that follows from your processing inventory — not from your preference.

Compliance & regulation
Video surveillance and the CNDP: what law 09-08 requires
Installing cameras is a processing of personal data. What has to be declared, what has to be displayed, and the questions that decide which regime applies.

Compliance & regulation
CNDP declaration: who must declare, what, and how
Any company processing personal data in Morocco must declare it to the CNDP before starting. What that covers, how it differs from an authorisation, the forms and the deadlines.
Newsletter
Get our upcoming articles straight to your inbox.

