RGPD & CNDP CABINET · FRANCE ↔ MOROCCO

Protect your data.
Prove your compliance.

RCM supports SMEs, international groups and service providers based in Morocco with GDPR and Morocco’s Law 09-08 compliance.

From audits and external DPO support to CNDP filings and international transfers, one expert team turns obligations into tracked actions and usable evidence.

ANSWER WITHIN 1 DAY EXTERNAL DPO LAW 09-08 · CNDP FRANCE ↔ MOROCCO
DIRECT ANSWER · GDPR MOROCCO

Who provides GDPR consulting services in Morocco?

RGPD Conseil Maroc (RCM) is a data protection consultancy based in Kenitra, Morocco. RCM supports organisations in Morocco, France and the European Union with GDPR, Morocco’s Law 09-08, CNDP filings, external DPO services, audits and international transfers. Each engagement is scoped around the client’s actual processing activities, risks and responsibilities.

GDPR MoroccoExternal DPOLaw 09-08CNDP
GDPR · EUROPEAN UNION LAW 09-08 · MAROC EXTERNAL DPO AUDIT · COMPLIANCE
FOR WHOM?

Where data
changes hands.

SOLUTIONS BY NEED

What do you need to
secure now?

Start with the outcome you need. Each solution combines the right expertise, even if you do not yet know which service to request.

OUR SERVICES

Six services.
One coherent programme.

Each engagement produces usable deliverables and can stand alone or form part of ongoing DPO support.

GDPR audit

Assess practices, evidence and risks to establish a realistic roadmap.

  • Interviews and documentary review
  • Differences by priority
  • Action plan assigned
Discover the audit →

Compliance programme

Build documentation and operating controls around your actual processing activities.

  • Records and policies
  • Notices and procedures
  • Governance and evidence
Build the base →

Privacy by design

Integrate data protection into projects before they go into production.

  • Risk qualification
  • DPIA and measures
  • Notices and arbitrations
Secure a project →

Processors

Assess suppliers and clarify responsibilities across the processing chain.

  • Article 28 clauses
  • Control questionnaires
  • Remediation plan
Review suppliers →

International transfers

Map France–Morocco access and flows, then document the necessary guarantees.

  • Clauses and evaluation
  • Additional measures
  • CNDP formalities
Analyze transfers →

Breaches and rights

Organise a prompt, proportionate and traceable response to rights requests and personal data breaches.

  • Qualification and register
  • Notifications and replies
  • Feedback
Prepare the response →
FRANCE ↔ MOROCCO

Two legal frameworks.
One coordinated approach.

The GDPR and Morocco’s Law 09-08 are not identical. We identify the obligations that apply to each organisation, role and data flow.

FRANCE · EUROPEAN UNION

GDPR

Accountability, documentation and protection of people throughout the data lifecycle.

  • Responsible/Processor roles
  • Register, bases and transparency
  • Guarantees for transfers outside the EEA
MAROC · CNDP

Law No. 09-08

Processing assessments, security, individual rights and the required CNDP formalities.

  • Declaration or authorization
  • Sensitive processing activities and CIN
  • Transfer abroad and F-118
OUR METHOD

Understand. Prioritise.
Implement. Maintain.

A method that is easy to explain, rigorous to apply and practical for your teams to maintain.

01 CARDAGE

Define the scope

Entities, teams, systems, data flows, countries, objectives and mission boundaries.

02 ANALYSIS

Review the evidence

Existing practices, documents, contracts, access controls, risks and regulatory formalities.

03 ACTION

Fix what matters

Deliverables, decisions, owners, deadlines and expected evidence.

04 PILOTAGE

Maintain compliance

Controls, new projects, incidents, rights requests and document updates.

CONTINUOUS SUPPORT

Clear starting points.
Scope before subscription.

Start with a known-price engagement. Move to monthly support only when the need becomes recurring.

FIXED-SCOPE PROJECT

Assessment & scope

€290 excl. VAT

MAD 3,200 excl. VAT. DPO meeting, review of five documents and a written scope within 48 hours.

Book the assessment →
ONGOING SUPPORT

DPO Operations

€890/month

MAD 9,800 excl. VAT/month. Defined volumes, maintained records, vendor review and reporting.

View the plan →
GDPR workspace Conseil Maroc
ABOUT RCM

A Moroccan base.
European expertise.

Founded by data protection professionals, RCM brings together experienced consultants and DPOs to make compliance practical, accessible and suited to both Moroccan and European requirements.

OFFICE Kenitra, Morocco
INTERVENTIONS France and Morocco
CONTACT +212 688-890602
TIMES 9 a.m. — 6 p.m.
About RCM →
FREQUENTLY ASKED QUESTIONS

Before you begin,
let’s clarify the essentials.

The right answer depends on your processing activities, your role, the people concerned and the countries involved.

Ask a question →
Can a Moroccan company support a French company?

Yes. A French company may appoint a service provider established in Morocco for consulting and certain compliance activities. RCM’s location does not remove the client’s duty to address contractual terms, confidentiality, security and, where personal data is accessed from Morocco, the applicable transfer mechanism outside the European Economic Area. Scope and responsibilities are agreed before work begins.

Are GDPR and Morocco’s Law 09-08 the same? +

No. Both frameworks protect individuals, but their scope, procedures and enforcement mechanisms differ. In Morocco, some processing activities may require a declaration or prior authorisation from the CNDP. The GDPR may also apply depending on an organisation’s establishment, activities and target audience. RCM assesses each framework separately before coordinating the resulting actions.

Does an external DPO replace the company's management? +

No. The DPO informs and advises the organisation, monitors compliance, supports DPIAs and cooperates with the competent supervisory authority. They must be able to act independently. Management remains responsible for processing purposes and means, budgets and risk decisions. Our support clearly separates DPO advice, operational actions and client decisions.

How long does it take to be compliant? +

There is no universal deadline, and compliance is not a permanent one-off achievement. A straightforward organisation may establish its priorities and core documentation within a few weeks, while one with many vendors, sensitive data or international transfers will need more work. After the assessment, we provide a phased roadmap with owners, deliverables and deadlines.

What do we actually receive after an audit? +

The agreed scope determines the deliverables. An RCM audit may include a map of the processing activities reviewed, gap analysis, risk classification, missing documentation, contractual issues and a prioritised action plan. A management debrief then explains the decisions, dependencies and recommended order of remediation.

Turn your next decision into
evidence of compliance.

Tell us about your organisation, any urgent issue and the countries involved. We’ll recommend the most suitable form of support.

Talk to a DPO