CNDP compliance & sensitive data
Your personal-data processing brought into compliance — and your platforms designed to stay that way.
Why this is surfacing now
Morocco's data-protection authority has stepped up enforcement, and the sectors it names as priorities include healthcare providers, pharmaceuticals, hospitality, e-commerce and higher education. Many companies have processed personal data for years without a prior declaration — often without knowing it was required.
The part directors discover late
Exposure is not only institutional. For sensitive data — health data included — the law provides for financial penalties and liability that can reach the director personally. This is not a topic to delegate to an IT supplier after the fact.
What we actually do
- Map the processing — what data, collected where, stored how long, accessible by whom, transmitted to whom.
- Gap analysis — what is missing against law 09-08: legal basis, informing data subjects, security, sub-processors.
- Declaration file — preparing the CNDP forms matching your processing activities.
- Technical remediation — fine-grained roles, access logging, encryption, automatic purge at end of retention, export and deletion on request.
- Audit documentation — enough to answer an inspection without reconstructing history under pressure.
Why us rather than a law firm
A legal opinion describes what ought to be true. Compliance actually happens in the software: who can see which record, what gets logged when someone opens it, what happens when the retention period expires. We do both halves — the analysis and the change to the system.
We apply this to ourselves
Our own processing follows the same logic: data minimisation, a preference for business contact details, defined retention periods. We can show you our approach before recommending it to you.
Ready to start your project?
Let's talk about your operation: we scope the roles and integrations first, then we price it.
