Customer environment
Access to production, support or copies of data from a team established in Morocco.
RCM
A Moroccan NSE can access the environments, tickets, newspapers, test bases or collaborative tools of a European customer without receiving a formally exported database. Such access remains a process to be mapped and may constitute transfers outside the European Economic Area. The contract, architecture and team practices must therefore tell the same story.
The risk often appears in the details: production copy used in acceptance, shared administrator account, undeclared freelance processor, repository containing data, support from Morocco or retention of a backup after the mission. RCM links these situations to the roles of the parties, the client's instructions, the applicable clauses and the actually demonstrable measures.
Our intervention does not transform a privacy review into a cybersecurity audit. It organizes the facts, evidence and corrections necessary to respond to a customer questionnaire, prepare a call for tenders or make an offshore development system sustainably verifiable.
Scoping starts with the facts: systems, teams, people involved, data, customers, suppliers and countries. The obligations are then qualified separately with regard to the GDPR and Moroccan law 09-08. This method avoids applying a generic response to processing activities that have neither the same purpose nor the same level of risk.
A mission may begin before a launch, during a negotiation or after a gap appears.
Access to production, support or copies of data from a team established in Morocco.
Security questionnaire, DPA, transfer clauses and proof requested before signing.
Freelancers, hosts, ticketing tools, code repositories and subsequent providers to be identified.
Decisions and limits are made visible at each stage.
Applications, teams, environments, data, countries, customers and processors.
Access, copies, logs, tools, transfers and deletion rules.
DPA, Article 28, standard contractual clauses, instructions and additional measures.
Supplier register, access matrix, incident procedure and customer file.
These situations are points of analysis, not automatic conclusions.
A realistic copy accelerates development but increases exposure and control obligations.
Administration accounts, remote access and secrets must be nominative, limited and traced.
A SaaS freelance or tool can change the contractual chain and the access locations.
The review meeting, deletion, revocation of accounts and preservation of evidence must be organized.
The service provider must detect, document and quickly report events to the principal.
The mechanism, context and measurements of the transfer must correspond to actual accesses.
Each check must have a responsible person, frequency and proportionate proof.
Fictitious or pseudonymized data by default, exceptional procedure for any production copy.
Nominative accounts, least privilege, periodic reviews and revocation upon exit.
Inventory of deposits, tickets, communications, hosts and processors.
Clauses, context assessment, additional measures and customer information.
Alert channel, minimum information, contractual deadlines and retention of facts.
End of mission checklist, verifiable deletion, review meeting and closure of access.
The final scope depends on maturity, risks and elements already available.
Applications, environments, teams, tools, access, data and countries.
Clauses article 28, instructions, assistance, audit, incident and fate of data.
CSC explained, transferred analysis and proposed additional measures.
Profiles, justification, approval, review and revocation.
Spoken responses, evidence available, discrepancies and responsible.
Stocks categorized by risk, effort, ownership and maturity.
The same activity may fall within both frameworks for different reasons.
Roles, responsibilities, information, rights, security, subcontracting and transfers outside EEA.
Treatment in Morocco, rights, security and formalities of declaration or authorization.
Access, hosting, recipients, mechanism, context and additional measures.
Contracts, registers, decisions, controls, training, incidents and actions followed.
The amounts are confirmed after scoping; no fictitious pricing is published.
Targeted interviews, review of available elements, major risks and sectoral roadmap.
Fixed price · after scopingAgreed deliverables, corrections, review meeting and operational transfer to internal managers.
From — on estimateVolume, deadlines, meetings, controls, new projects and contract overruns.
Subscription · on quoteRCM provides GDPR advice, law 09-08 and operational assistance. The client organization retains its decisions, responsibilities, budgets, validations and technical actions. No mission guarantees absolute compliance, absence of sanction or a favorable decision from an authority.
These answers present general principles. Processing, roles, countries and contracts should be reviewed before any conclusion.
Remote access from a third country may constitute a transfer even if the data remain hosted in the Union. It is necessary to examine who has access, under what authority, for what purposes and with what guarantees. RCM documents the actual scenario before recommending the appropriate mechanism and measures.
This choice must remain exceptional, justified and surrounded by strict measures. The priority is to use fictitious, synthetic or properly pseudonymized data. When real data is essential, the perimeter, access, duration, security and deletion must be precisely validated and traced.
No. RCM examines evidence, access governance and consistency of privacy responses. Penetration tests, code reviews, architectural audits and technical investigations are carried out by cybersecurity specialists. We can coordinate findings that influence data protection.
The contract should reflect actual roles and, when it comes to outsourcing, cover the requirements of Article 28: instructions, confidentiality, security, sub-processors, support, incidents, audit and fate of data. Transfers require separate processing consistent with access from Morocco.
Present verifiable evidence: access matrix, applied policies, sample reviews, incident procedure, processor register, training and remediation plan. RCM avoids absolute statements and clearly distinguishes between present controls, available evidence and planned improvements.
RCM verifies the implications of Law 09-08, particularly for processing activities and transfers falling within Morocco. A possible CNDP formality is prepared in a separate scope, validated and signed by the organization concerned.
Present your tools, data, customers, suppliers, countries and deadlines. RCM will indicate the first useful perimeter.
Scoping the mission →