New program
Collection of beneficiaries, survey, help, support or field research.
RCM
An association can handle few cases but a lot of sensitive information: vulnerability, health, family status, opinions, convictions, assistance received or location. The confidence of beneficiaries, members and donors depends on measured use and communication that does not expose them.
Permanent teams, volunteers, donors, partners, donation platforms, free tools and international service providers create a specific governance. A person can have several roles and a file created for one project should not be automatically reused for another campaign.
RCM offers compliance proportionate to the organization's resources: prioritizing risky processing, clarifying responsibilities, limiting access, supervising partners and producing essential evidence. The mission does not cover the complete regulation of associations, financing or social programs.
Scoping starts with the facts: systems, teams, people involved, data, customers, suppliers and countries. The obligations are then qualified separately with regard to the GDPR and Moroccan law 09-08. This method avoids applying a generic response to processing activities that have neither the same purpose nor the same level of risk.
A mission may begin before a launch, during a negotiation or after a gap appears.
Collection of beneficiaries, survey, help, support or field research.
Questionnaire, sharing agreement, hosting or nominative reporting requested.
Donations, petition, newsletter, testimonials, photos or event.
Decisions and limits are made visible at each stage.
Members, volunteers, donors, beneficiaries, employees, partners and public.
Sensitivity, vulnerability, volume, publication, countries and possible consequences.
Information, choice, access, sharing, conservation, contracts and security.
Simple, accountable templates, training, controls and project closure.
These situations are points of analysis, not automatic conclusions.
Disclosure can result in stigma, discrimination or physical risk.
Program contact information does not automatically become a campaign list.
The roles and responsibilities for collecting, sharing, reporting and curation should be explicit.
Text, photo, location or personal history can identify a person.
The business model, countries, accounts and data reuse must be verified.
Data should not remain in project accounts and devices indefinitely.
Each check must have a responsible person, frequency and proportionate proof.
Request only information useful for the service, follow-up or proof required.
Separate access, lists, purposes and durations for each activity when necessary.
Contextualized validation, anonymization, removal and re-identification risk verification.
Agreement on roles, uses, security, incidents, rights and fate of data.
Inventory, justified archive, deletion, review meeting and revocation of access.
Simple rules on collection, messaging, devices, photos, sharing and reporting.
The final scope depends on maturity, risks and elements already available.
Programs, people, data, tools, partners and countries.
Essential treatment and special risks for beneficiaries.
Notices, forms, contextualized consents and minimization rules.
Clauses and matrix of responsibilities for sharing or subcontracting.
Decision, information, image, anonymization, publication and withdrawal.
Checklist for launch and closure, access, retention and incident.
The same activity may fall within both frameworks for different reasons.
Roles, responsibilities, information, rights, security, subcontracting and transfers outside EEA.
Treatment in Morocco, rights, security and formalities of declaration or authorization.
Access, hosting, recipients, mechanism, context and additional measures.
Contracts, registers, decisions, controls, training, incidents and actions followed.
The amounts are confirmed after scoping; no fictitious pricing is published.
Targeted interviews, review of available elements, major risks and sectoral roadmap.
Fixed price · after scopingAgreed deliverables, corrections, review meeting and operational transfer to internal managers.
From — on estimateVolume, deadlines, meetings, controls, new projects and contract overruns.
Subscription · on quoteRCM provides GDPR advice, law 09-08 and operational assistance. The client organization retains its decisions, responsibilities, budgets, validations and technical actions. No mission guarantees absolute compliance, absence of sanction or a favorable decision from an authority.
These answers present general principles. Processing, roles, countries and contracts should be reviewed before any conclusion.
No. The non-profit nature does not remove data protection obligations. The scope depends on the processing activities, people, places and means used. A proportionate approach allows efforts to be focused on the most significant risks without replicating the governance of a large group.
The agreement must be free, understandable and sufficiently precise, particularly in situations of vulnerability or dependence. The medium, audience, duration, possibility of removal and risk of re-identification must be considered. An anonymized alternative should be favored when exposure is not necessary.
The request must be linked to a purpose, a necessity and a sharing framework. It should be considered whether aggregated or pseudonymized data is sufficient, who will receive the information, in which country, how securely and for how long. The financing contract does not automatically settle all these points.
The organization should reduce local copying, offer approved channels, protect accounts, plan for reporting, and arrange for deletion at the end of the engagement. A short charter and practical training are often more effective than a general policy that is not applied.
It is necessary to distinguish between the management of the donation, the obligations of proof and future communication. The information, the channel, the choices and the right to object must be organized. A list received from a partner or created for an event must not be reused without analysis.
No. RCM intervenes on the protection of personal data. Obligations relating to status, financing, taxation, anti-money laundering or social programs are handled by competent specialists.
Present your tools, data, customers, suppliers, countries and deadlines. RCM will indicate the first useful perimeter.
Scoping the mission →