ESN · SOFTWARE · OFFSHORE TEAMS

Build from Morocco.
Keep client data under control.

A Moroccan NSE can access the environments, tickets, newspapers, test bases or collaborative tools of a European customer without receiving a formally exported database. Such access remains a process to be mapped and may constitute transfers outside the European Economic Area. The contract, architecture and team practices must therefore tell the same story.

Article 28TEST DATAREMOTE ACCESSTRANSFERS

Your activity,
its real flows.

The risk often appears in the details: production copy used in acceptance, shared administrator account, undeclared freelance processor, repository containing data, support from Morocco or retention of a backup after the mission. RCM links these situations to the roles of the parties, the client's instructions, the applicable clauses and the actually demonstrable measures.

Our intervention does not transform a privacy review into a cybersecurity audit. It organizes the facts, evidence and corrections necessary to respond to a customer questionnaire, prepare a call for tenders or make an offshore development system sustainably verifiable.

Scoping starts with the facts: systems, teams, people involved, data, customers, suppliers and countries. The obligations are then qualified separately with regard to the GDPR and Moroccan law 09-08. This method avoids applying a generic response to processing activities that have neither the same purpose nor the same level of risk.

WHEN TO COME

Triggers
most common.

A mission may begin before a launch, during a negotiation or after a gap appears.

01

Customer environment

Access to production, support or copies of data from a team established in Morocco.

02

New European contract

Security questionnaire, DPA, transfer clauses and proof requested before signing.

03

Subcontracting chain

Freelancers, hosts, ticketing tools, code repositories and subsequent providers to be identified.

FROM THE FIELD TO EVIDENCE

A journey
in four stages.

Decisions and limits are made visible at each stage.

01

Frame

Applications, teams, environments, data, countries, customers and processors.

02

Trace

Access, copies, logs, tools, transfers and deletion rules.

03

Frame

DPA, Article 28, standard contractual clauses, instructions and additional measures.

04

Prove

Supplier register, access matrix, incident procedure and customer file.

SECTORAL RISKS

What the documents
Don't always show.

These situations are points of analysis, not automatic conclusions.

01

Production data under test

A realistic copy accelerates development but increases exposure and control obligations.

02

Technical privileges

Administration accounts, remote access and secrets must be nominative, limited and traced.

03

Invisible processors

A SaaS freelance or tool can change the contractual chain and the access locations.

04

End of mission

The review meeting, deletion, revocation of accounts and preservation of evidence must be organized.

05

Incidents and delays

The service provider must detect, document and quickly report events to the principal.

06

EU–Morocco transfer

The mechanism, context and measurements of the transfer must correspond to actual accesses.

OPERATIONAL CONTROLS

Measures that
teams can apply.

Each check must have a responsible person, frequency and proportionate proof.

01

Separate environments

Fictitious or pseudonymized data by default, exceptional procedure for any production copy.

02

Manage authorizations

Nominative accounts, least privilege, periodic reviews and revocation upon exit.

03

Master the tools

Inventory of deposits, tickets, communications, hosts and processors.

04

Document the transfer

Clauses, context assessment, additional measures and customer information.

05

Prepare for the incident

Alert channel, minimum information, contractual deadlines and retention of facts.

06

Close properly

End of mission checklist, verifiable deletion, review meeting and closure of access.

DELIVERY

What RCM
Leave it to your teams.

The final scope depends on maturity, risks and elements already available.

01

Technical mapping

Applications, environments, teams, tools, access, data and countries.

02

DPA Review

Clauses article 28, instructions, assistance, audit, incident and fate of data.

03

Transfer file

CSC explained, transferred analysis and proposed additional measures.

04

Access Matrix

Profiles, justification, approval, review and revocation.

05

Customer questionnaire kit

Spoken responses, evidence available, discrepancies and responsible.

06

Remediation plan

Stocks categorized by risk, effort, ownership and maturity.

TWO FRAMES

GDPR and law 09-08,
I didn't confuse them.

The same activity may fall within both frameworks for different reasons.

EU

GDPR

Roles, responsibilities, information, rights, security, subcontracting and transfers outside EEA.

MA

Law 09-08

Treatment in Morocco, rights, security and formalities of declaration or authorization.

International flows

Access, hosting, recipients, mechanism, context and additional measures.

Evidence

Contracts, registers, decisions, controls, training, incidents and actions followed.

INTERVENTION FORMATS

Start small.
Maintain if necessary.

The amounts are confirmed after scoping; no fictitious pricing is published.

DIAGNOSIS

Starting point

Targeted interviews, review of available elements, major risks and sectoral roadmap.

Fixed price · after scoping
TARGETED MISSION

Priority base

Agreed deliverables, corrections, review meeting and operational transfer to internal managers.

From — on estimate
ACCOMPANYING

Continuous management

Volume, deadlines, meetings, controls, new projects and contract overruns.

Subscription · on quote
RESPONSIBILITIES AND LIMITS

Advise, structure
and advance.

RCM provides GDPR advice, law 09-08 and operational assistance. The client organization retains its decisions, responsibilities, budgets, validations and technical actions. No mission guarantees absolute compliance, absence of sanction or a favorable decision from an authority.

  • Penetration tests, forensic investigations and certifications are carried out by competent experts.
  • Reserved legal consultations and litigation are directed to a lawyer.
  • Sectoral regulations excluding data protection remain outside the scope unless expressly stated.
FREQUENTLY ASKED QUESTIONS

Specific responses.
Contextualized decisions.

These answers present general principles. Processing, roles, countries and contracts should be reviewed before any conclusion.

Does a team in Morocco connect to a European server make a transfer?

Remote access from a third country may constitute a transfer even if the data remain hosted in the Union. It is necessary to examine who has access, under what authority, for what purposes and with what guarantees. RCM documents the actual scenario before recommending the appropriate mechanism and measures.

Can we use production data for testing? +

This choice must remain exceptional, justified and surrounded by strict measures. The priority is to use fictitious, synthetic or properly pseudonymized data. When real data is essential, the perimeter, access, duration, security and deletion must be precisely validated and traced.

Does RCM perform a penetration test? +

No. RCM examines evidence, access governance and consistency of privacy responses. Penetration tests, code reviews, architectural audits and technical investigations are carried out by cybersecurity specialists. We can coordinate findings that influence data protection.

What should the contract with the European customer contain? +

The contract should reflect actual roles and, when it comes to outsourcing, cover the requirements of Article 28: instructions, confidentiality, security, sub-processors, support, incidents, audit and fate of data. Transfers require separate processing consistent with access from Morocco.

How to reassure a prospect without pretending to be certified? +

Present verifiable evidence: access matrix, applied policies, sample reviews, incident procedure, processor register, training and remediation plan. RCM avoids absolute statements and clearly distinguishes between present controls, available evidence and planned improvements.

Does the offer cover Moroccan formalities? +

RCM verifies the implications of Law 09-08, particularly for processing activities and transfers falling within Morocco. A possible CNDP formality is prepared in a separate scope, validated and signed by the organization concerned.

Your sector deserves A concrete scoping.

Present your tools, data, customers, suppliers, countries and deadlines. RCM will indicate the first useful perimeter.

Scoping the mission →
Talk to a DPO