Solutions
Product
Pricing
Resources
Start free trial

Morocco School Data Protection: CNDP Checklist

Morocco School Data Protection: CNDP Checklist

School app data protection in Morocco is not decided by the app’s privacy page. It is decided by a file the school itself has to be able to produce.

Before a Moroccan school signs a parent-communication app, it needs a file it can hand to the CNDP. That file has three parts: a déclaration préalable covering the processing, extracts of the processor contract evidencing the technical and organisational security measures, and — if the vendor stores anything outside Morocco — a prior authorisation under articles 43 and 44 of Law 09-08. The second item is required where applicable (le cas échéant, in the regulator’s own wording) (CNDP).

Under Law 09-08 the filing duty sits with the responsable de traitement, and in the public national-education system the controller can be legally represented at establishment level — a 2023 joint CNDP–Education Ministry guide, written for video surveillance, lists “Le Directeur au niveau des établissements scolaires” alongside the Minister, the AREF Director and the provincial Délégué as possible legal representatives (CNDP/MEN). The vendor’s job is to make your filing possible. Here is how to check whether it can.

School app data protection in Morocco: six checks before you sign

Run these six against any shortlisted vendor. Every one maps to a document the CNDP can ask you — the school — to produce.

#CheckWhat Law 09-08 asks of the schoolWhat to ask the vendor
1Declaration routeEvery processing operation needs a déclaration préalable unless it is out of scope, exempted, or bumped to autorisation préalable”Which form applies to a parent-communication deployment, and can you supply the processing description we file?“
2Processor contract extractsThe filing may require “extraits de contrat de sous-traitance garantissant les mesures de sécurité technique et d’organisation""Send the clause set naming our establishment, before contract signature, not after”
3Hosting locationCross-border transfer is governed by articles 43–44; in practice the CNDP asks for prior authorisation for transfers to all destinations”Where are the databases, the backups, and the support team’s access?“
4Purpose limitationUsing data beyond the declared purpose is détournement de finalité”Is any pupil or parent data used for analytics, model training, or marketing?“
5RetentionThe CNDP’s 2025 decisions tie retention to necessity — its cookie decision caps cookie data at six months”What is the deletion schedule per data type, and who triggers it?“
6Breach handlingLaw 09-08 imposes no notification duty on you — so your contract has to create one”How fast do you notify us, in writing, and with what detail?”

Three of those rows name documents most schools have never seen. What they look like in practice:

  • Row 1 — the processing description. A half-page the vendor supplies and you paste into the déclaration: purpose (“communication établissement–parents: annonces, absences, réunions”), data categories (pupil first and last name, class, parent name, one mobile number, one email), recipients (teachers of the class, the head teacher, the vendor as sous-traitant), retention (deleted 12 months after the pupil leaves), and the hosting country in one line.
  • Row 2 — the processor contract extracts. A two-page annex naming your establishment in the header — not the AREF, not the ministry — listing encryption at rest and in transit, named roles with database access, the subcontractor list, and a return-or-destroy clause at contract end. Request it at RFP stage, because after signature the vendor has no reason to re-open the paper.
  • Row 6 — the breach clause the law does not require. One sentence: “The processor shall notify the establishment in writing within 48 hours of confirming any unauthorised access to or disclosure of pupil or parent data, stating the number of records affected, the categories of data involved, and the remediation steps taken.” It goes in the contract, because Law 09-08 gives you nothing here.

Expect checks 3 and 6 to be the hardest for a vendor to answer, and treat a vague answer as an answer: a vendor that cannot tell you which country its backups sit in cannot help you draft a transfer request. Row 5 is where a documents module earns its place — deletion schedules only hold if someone can see what is stored and for how long.

The CNDP filing timeline: 24 hours, 8 days, 2 months

The mechanics are quick to state. The CNDP issues the récépissé de déclaration within 24 hours. It has 8 days to notify you that it is escalating the processing to autorisation préalable if it judges the processing presents manifest dangers to privacy and fundamental rights. An authorisation opinion is notified within 2 months — a deadline the CNDP can extend once, and one that only starts running when your file is complete, since an incomplete application does not start the clock until the requested documents are supplied (CNDP). Model declarations for customer, supplier and HR processing have existed since 2015 (Digital Policy Alert); none of the three covers parent communication or pupil data, so they show the filing machinery exists without giving you a ready-made form for this processing.

Two months is the number that matters for procurement, and it is a floor rather than a ceiling. If your chosen vendor hosts abroad, article 43–44 transfer authorisation applies — a separate authorisation from the processing declaration, required for each notified or authorised processing according to the Chambers guide. That clock lands between your signature and your go-live, not after it.

What changed at the CNDP in 2025

For roughly fifteen years the CNDP’s posture was educational. The Chambers 2026 Morocco guide, written by DLA Piper’s Casablanca office, describes it precisely: the regulator “has focused, for over a decade, on familiarising stakeholders with the applicable data protection regulations”, and only “over the last few months” began issuing warnings to major controllers and opening investigations (Chambers). Those warnings went to hotels, pharmaceutical companies, public universities and other public bodies.

The sector sequence was reported in May 2025: healthcare first, with roughly 3,000 pharmacists taking alignment steps, then lawyers, notaries, court clerks and media outlets. The letters carry multi-month action plans and an explicit warning that delay may bring penalties. And the regulator named what comes next: “the CNDP plans to widen the compliance program to include education, banking, insurance, e-commerce, and digital services in the coming months” (Hespress). Read the timestamp carefully: “the coming months” was said in May 2025, roughly fifteen months before this article, and no public source documents the education phase having started.

Treat that as an announcement, not a documented school case. No enforcement action against a named Moroccan school or a named school-app vendor is on the public record. What is on the record is that the CNDP’s sector-by-sector method keeps running: DATA-TIKA conventions with Crédit Agricole du Maroc and the Ministère de l’Agriculture in April 2026, the Ordre des Experts comptables in April 2026, the Ordre National des Huissiers de Justice received in June 2026 (CNDP). One profession or ministry at a time, with dates. Our own reading is that this cadence makes “education is next” worth planning around.

The inspection powers themselves are set out plainly. The CNDP’s own mandate page states its agents “peuvent accéder directement à tous les éléments intervenant dans les processus de traitement (les données, les équipements, les locaux, les supports d’information)”, and that such checks can lead to administrative, financial or criminal sanctions (CNDP). What the 2025 reporting documents is a change in activity — warnings and investigations where there was outreach — against a mandate the regulator’s own page already describes.

What Law 09-08 requires, and what it leaves out

This is where schools that have read about the GDPR go wrong. Law 09-08, promulgated in 2009, reproduces the logic of Directive 95/46/EC. It is declarative and authorisation-based, built on the regulator’s prior control rather than on continuous accountability by the organisation. A legal analysis published in December 2025 lists what it therefore lacks: “accountability, analyse d’impact (DPIA), privacy by design/by default, portabilité des données, registre interne des traitements, notification des violations de données” (Village de la Justice). Every item on that list is one a school arriving from a European frame of reference expects to find, and our guide to GDPR-compliant school communication covers what those obligations look like where they do apply. The Chambers guide agrees on breach notification: controllers and processors are not required to notify the authority, though doing so is highly recommended.

Our free CNIL consent form generator turns the same question into a score you can act on.

Two practical consequences for procurement.

First, if the obligation is a Moroccan déclaration and Morocco has not obtained an EU adequacy decision, then a vendor’s “GDPR-compliant” badge is answering a different question than the one your file asks. Nothing in the sources treats one as evidence of the other. Second, because nothing in the statute obliges you to keep an internal register or run an impact assessment, your entire evidential position is the filing and the contract. If those are thin, there is nothing else to point at.

Where vendors fail on pupil data in Morocco

Consumer messaging groups. Work check 2 backwards for a school running parent communication through a consumer WhatsApp or Telegram group. If the CNDP asks for extracts of a contrat de sous-traitance, a school would need such a contract with the messaging provider to extract clauses from — and would need to be able to state where message content and parents’ phone numbers are stored. No source in the record documents how these providers contract with Moroccan schools, so treat this as the question to put to your own file. The convenience is real; whether the filing can be built on it is something the school has to establish. The alternative is a bounded messaging channel whose participants, retention and storage location you can describe on a form, with SMS for the parents who never install anything — the group that most often pushes a school back into an unbounded consumer group in the first place.

International parent apps. If your shortlist includes an international parent app — ClassDojo, Seesaw and Remind are the names that come up most often — the question to put to each is which country its primary database, its backups and its support access sit in. These products are typically hosted outside Morocco, and which country applies has to be confirmed per vendor. If the answer is the EU, that is the easier case: the CNDP’s approved list covers EU member states, Iceland, Liechtenstein, Norway, Switzerland, Canada and the United Kingdom (Digital Policy Alert). But approved does not mean automatic — the Chambers guide reports that in practice the CNDP requires prior authorisation for transfers to all countries, with approval granted more easily for listed destinations. For non-listed destinations the request must include the transferor’s and recipient’s names and addresses, data categories, individuals concerned, and the purpose, mode and frequency of the transfer (Digital Policy Alert) — and because authorisation is sought for all countries in practice, that is the detail set worth collecting from any vendor, wherever it hosts.

School ERP and gradebook suites. Where a suite processes more than messages — grades, attendance, health notes, access-control data — the declared purpose has to stretch to cover all of it. That applies to any school-management platform on your list, Pronote-style gradebook suites included. The logic of the regime is straightforward: détournement de finalité is defined by the gap between what was declared and what is done, so the broader the declared scope, the more surface there is for that gap to open. Mapping the workflows a school actually runs against the purpose you intend to declare is the cheapest way to find that gap before the CNDP does.

The cost side. Non-compliance with Law 09-08 carries a fine of MAD 10,000 to MAD 600,000 and/or imprisonment of three months to four years, per the Chambers guide. The 2023 CNDP–Education Ministry guide states the article 54 penalty for détournement de finalité specifically: three months to one year and a fine of 20,000 to 200,000 DH, or one of the two penalties alone. Note the sources are not uniform on the sanction route: the CNDP’s mandate page says its controls can give rise to administrative, financial or criminal sanctions, while the December 2025 legal analysis describes the framework as lacking administrative fines.

The honest reckoning: other reasons 2025 looks like this

The enforcement turn is not only a regulator maturing, and a school planning around it should know the other forces. Morocco is positioning itself as a continental data-governance reference while still pursuing an EU adequacy decision it does not yet hold (Chambers). And data protection is one strand of a whole-of-government digital push — the Digital Morocco 2030 strategy, the cybersecurity law implemented in July 2020, a bill to establish a national AI governance agency (Digital Policy Alert). Any of these can shift the pace of a sector campaign. None of them makes the school’s filing obligation go away, because that obligation predates all of them.

What to do before the next contract renewal

1. Put the six checks in the tender, not the negotiation. In practice, this looks like a one-page annex attached to every RFP you send, with the six questions above, a required written answer per question, and a rule that an unanswered row disqualifies — triggered automatically whenever a communication tool is added or renewed.

2. Get the hosting answer in writing before shortlisting. In practice, this looks like a single email, sent at first contact, asking for the country of primary storage, the country of backups, and the country from which support staff can read school data — with a 5-working-day reply deadline, because an authorisation opinion runs to two months and can be extended once.

In the same email, ask for the fields the CNDP will ask you for in a transfer request: the transferor’s and recipient’s names and addresses, the data categories, the individuals concerned, and the purpose, mode and frequency of the transfer. A vendor that can return those in a week can be filed; one that cannot will cost you the two-month clock twice.

3. Name the responsable de traitement internally. In practice, this looks like the head teacher’s name written into the declaration file and a 20-minute handover at the start of each school year covering what was declared, for what purpose, and who holds the récépissé.

4. Make the vendor create the breach duty the law does not. In practice, this looks like one contract clause requiring written notice to the school within 48 hours of a confirmed incident, with affected record counts and remediation steps — reviewed once a year at renewal.

The requirement is narrow and it is documentary: a Moroccan school must be able to show, on request, what it declared, what its processor guarantees, and where the data physically sits. What you therefore need from a platform is hosting you can name on a form, per-establishment processor terms you can extract clauses from, and data collection scoped to the purpose you declared. BeeNet is one implementation path; there are others, and the right test is whether a vendor can fill your six rows in writing. Our security page states the hosting region — the EU, which is on the CNDP’s approved list, though as above, approved still means requesting authorisation — and what the processor terms cover; a 15-minute demo walks the six rows one at a time.

The CNDP said in May 2025 that education is next. The only question is whether your file is ready when the letter arrives or written in a hurry after it does.

References

  1. CNDP. Formalités — déclaration préalable, autorisation préalable, pièces justificatives, délais, transfert à l’étranger. Commission Nationale de Contrôle de la Protection des Données à Caractère Personnel. https://www.cndp.ma/formalites/
  2. Lechheb, Imane. Morocco enforces data privacy law, warns companies of penalties. Hespress English, 23 May 2025. https://en.hespress.com/111530-morocco-enforces-data-privacy-law-warns-companies-of-penalties.html
  3. Kettani, Mehdi; Mouline, Adil; Sentissi, Othman; Mouti, Kawtar (DLA Piper Casablanca). Data Protection & Privacy 2026 — Morocco. Chambers Global Practice Guides, updated 10 March 2026. https://practiceguides.chambers.com/practice-guides/data-protection-privacy-2026/morocco
  4. Garno, Zakaria. Du cadre de la loi 09-08 au leadership africain : la CNDP comme architecte du modèle marocain de gouvernance des données. Village de la Justice, 12 December 2025. https://www.village-justice.com/articles/cadre-leadership-africain-cndp-comme-architecte-modele-marocain-gouvernance-des,55421.html
  5. CNDP. Délibérations et actualités — activity archive 2025–2026. https://www.cndp.ma/deliberations/
  6. CNDP and Ministère de l’Éducation Nationale. Guide de l’utilisation de la vidéosurveillance dans les institutions relevant du secteur de l’éducation nationale. January 2023. https://www.cndp.ma/wp-content/uploads/2023/01/guide_CNDP_VS_MEN_fr.pdf
  7. CNDP. Missions — contrôle et investigation. https://www.cndp.ma/missions/
  8. Buza, Maria; Taha, Sherif. DPA Digital Digest: Morocco [2025 Edition]. Digital Policy Alert, St. Gallen Endowment for Prosperity Through Trade, 9 April 2025. https://digitalpolicyalert.org/digest/dpa-digital-digest-morocco

Continue reading

Ready to Transform Your School Communication?

Start saving time and increasing parent engagement with BeeNet.

Request Demo