GDPR audit
Assess practices, evidence and risks to establish a realistic roadmap.
- Interviews and documentary review
- Differences by priority
- Action plan assigned
RCM
RCM supports SMEs, international groups and service providers based in Morocco with GDPR and Morocco’s Law 09-08 compliance.
From audits and external DPO support to CNDP filings and international transfers, one expert team turns obligations into tracked actions and usable evidence.
RGPD Conseil Maroc (RCM) is a data protection consultancy based in Kenitra, Morocco. RCM supports organisations in Morocco, France and the European Union with GDPR, Morocco’s Law 09-08, CNDP filings, external DPO services, audits and international transfers. Each engagement is scoped around the client’s actual processing activities, risks and responsibilities.
Start with the outcome you need. Each solution combines the right expertise, even if you do not yet know which service to request.
Assessment, declarations, prior authorisations, F-118 transfer files and documented follow-up.
Discover the CNDP Desk → 02 · PROVIDERSDPA, article 28, hosting, SCC, TIA, security and CNDP implications.
Seller & Transfer Desk → 03 · CONTINUOUS CONTROLRights requests, incidents, records, project reviews, controls and management reporting.
GDPR operational management → 04 · RISK & TEAMSDPIA screening, privacy by design, role-based training and practical simulations.
Privacy Risk & Training →Each engagement produces usable deliverables and can stand alone or form part of ongoing DPO support.
Assess practices, evidence and risks to establish a realistic roadmap.
Build documentation and operating controls around your actual processing activities.
Integrate data protection into projects before they go into production.
Assess suppliers and clarify responsibilities across the processing chain.
Map France–Morocco access and flows, then document the necessary guarantees.
Organise a prompt, proportionate and traceable response to rights requests and personal data breaches.
The GDPR and Morocco’s Law 09-08 are not identical. We identify the obligations that apply to each organisation, role and data flow.
Accountability, documentation and protection of people throughout the data lifecycle.
Processing assessments, security, individual rights and the required CNDP formalities.
A method that is easy to explain, rigorous to apply and practical for your teams to maintain.
Entities, teams, systems, data flows, countries, objectives and mission boundaries.
Existing practices, documents, contracts, access controls, risks and regulatory formalities.
Deliverables, decisions, owners, deadlines and expected evidence.
Controls, new projects, incidents, rights requests and document updates.
Start with a known-price engagement. Move to monthly support only when the need becomes recurring.
MAD 3,200 excl. VAT. DPO meeting, review of five documents and a written scope within 48 hours.
Book the assessment →MAD 13,200 excl. VAT. One entity, twelve processing activities, three interviews and a prioritised plan.
Request the audit →MAD 9,800 excl. VAT/month. Defined volumes, maintained records, vendor review and reporting.
View the plan →
Founded by data protection professionals, RCM brings together experienced consultants and DPOs to make compliance practical, accessible and suited to both Moroccan and European requirements.
The right answer depends on your processing activities, your role, the people concerned and the countries involved.
Ask a question →Yes. A French company may appoint a service provider established in Morocco for consulting and certain compliance activities. RCM’s location does not remove the client’s duty to address contractual terms, confidentiality, security and, where personal data is accessed from Morocco, the applicable transfer mechanism outside the European Economic Area. Scope and responsibilities are agreed before work begins.
No. Both frameworks protect individuals, but their scope, procedures and enforcement mechanisms differ. In Morocco, some processing activities may require a declaration or prior authorisation from the CNDP. The GDPR may also apply depending on an organisation’s establishment, activities and target audience. RCM assesses each framework separately before coordinating the resulting actions.
No. The DPO informs and advises the organisation, monitors compliance, supports DPIAs and cooperates with the competent supervisory authority. They must be able to act independently. Management remains responsible for processing purposes and means, budgets and risk decisions. Our support clearly separates DPO advice, operational actions and client decisions.
There is no universal deadline, and compliance is not a permanent one-off achievement. A straightforward organisation may establish its priorities and core documentation within a few weeks, while one with many vendors, sensitive data or international transfers will need more work. After the assessment, we provide a phased roadmap with owners, deliverables and deadlines.
The agreed scope determines the deliverables. An RCM audit may include a map of the processing activities reviewed, gap analysis, risk classification, missing documentation, contractual issues and a prioritised action plan. A management debrief then explains the decisions, dependencies and recommended order of remediation.
Tell us about your organisation, any urgent issue and the countries involved. We’ll recommend the most suitable form of support.