Compliance

Websites and personal data: CNDP compliance in Morocco

The moment a site collects a name and an email address it is processing personal data. In Morocco that processing falls under law 09-08 and is declared to the CNDP.

· 7 min read · Noor Studio Agency

Preview of a management interface designed by Noor Studio Agency

What exactly is covered

Morocco's law 09-08 on the protection of individuals with regard to the processing of personal data governs how such data is collected and used. It is overseen by the CNDP, the national commission for the protection of personal data.

Many business owners assume this only concerns large customer databases. The scope is wider: a contact form, a newsletter sign-up, a client area, order tracking — each of those is personal data processing. The CNDP states that the manager of a website collecting and processing personal data must notify it of the processing carried out, and that the online declaration is free.

This guide describes what that means for building a site. It is not legal advice: for your specific situation the source to consult is the CNDP itself, and your counsel if the processing is sensitive.

The principles that turn into design decisions

Three principles in the text have direct, concrete consequences for a website.

  • Fairness and transparency. The person must know who is collecting, why, and what becomes of their data. In practice: a readable privacy policy, and a notice at the point of collection — not only buried in the footer.
  • Proportionality. Collect only what is strictly necessary for the stated purpose. This is the most commonly broken principle, and out of convenience: a contact form asking for a full postal address, a date of birth or an ID number collects beyond what making contact justifies. The principle happens to coincide exactly with what improves conversion — fewer fields, more replies.
  • Individual rights. Access, rectification and objection. That requires a way to reach you to exercise them, and knowing where the data sits so you can act on the request.

What it changes in a web project

Translated into site elements, that gives a short and checkable list.

  • A real privacy policy, stating which data is collected, why, how long it is kept and who it is shared with. Generic text copied from another site describes somebody else's processing.
  • A form reduced to what is needed, with the purpose stated where the collection happens.
  • Separate consent for marketing. Agreeing to be contacted about a quote is not agreeing to a newsletter. Two purposes, two boxes — and never pre-ticked.
  • Awareness of what third-party tools do. An analytics tool, an advertising pixel or a hosted chat widget process data from your site. They belong in what you must be able to describe.
  • Knowing where the data lands. A database at a host, an inbox, a shared spreadsheet: every copy is a place the data exists, and where an access request will have to be answered.

The most common mistake: copying a European text

Many Moroccan sites publish a privacy policy that cites the GDPR, mentions a data protection officer and points to a European authority. That is a text taken from elsewhere, describing a framework that is not the one in force.

The GDPR can apply to a Moroccan business in one specific case: when it targets people located in the European Union. A travel agency selling to French customers, an online store shipping to Europe, a studio working for European clients are in that position. They then fall under both frameworks, not one.

For everyone the rule is the same: the published text must describe what your site does. A template gives you a structure, never the content.

Where to actually start

Compliance looks vast because it gets framed in legal terms. Framed as an inventory, it takes half a day for a mid-sized business.

  • List the collection points. Every form, every sign-up, every client area, every tool that drops an identifier. Open the site and write them down one by one.
  • For each one, write the purpose in a sentence. If the sentence is hard to write, the collection usually has no reason — and the answer is to remove it rather than declare it.
  • Follow where each piece of data goes. Database, inbox, spreadsheet, external tool. Every destination is somewhere an access request will have to be honoured.
  • Delete the fields with no purpose, and the tools whose data nobody reads. This is the step that most reduces the work left.
  • Write the policy from that inventory, then file the declaration. In that order: the text then describes what you actually do.

Frequently asked

Does a simple brochure site count?

As soon as it has a contact form, it collects personal data. A strictly static site with no form, no client area and no identifying analytics collects far less — but that is rare in practice.

Who is responsible, my agency or me?

The controller is whoever decides why and how the data is collected: the business, not the supplier who builds the tool. The agency has a technical role and a duty to advise; it does not take the controller's place.

Is the declaration paid?

The CNDP states that the online declaration is free. The real cost of compliance sits elsewhere: in the time spent inventorying what you collect and where it ends up.

And at Noor Studio Agency?

We design forms lean — three fields rather than eight — and document at handover what the site collects and where it lands. That helps with compliance, and it is exactly what makes a form get replies.

A look at your current site

Send us the address. We will tell you what is costing you most today, what can be fixed without a rebuild, and what is not worth doing.