Why CNDP compliance has become a law-firm management issue
A colleague in Casablanca once told me, with complete confidence, that his files were outside the reach of the CNDP because every document in his office was protected by professional secrecy. His reasoning sounded plausible. It was also wrong. Professional secrecy governs what a lawyer may disclose and protects the substance of the lawyer-client relationship; it does not remove a practice from the formalities, security requirements and accountability mechanisms imposed by Moroccan data protection law.
Every day, a Moroccan lawyer processes names, CNIE numbers, telephone numbers, bank statements, family circumstances, medical reports, criminal records, employment files and confidential corporate documents. Some of this information is merely personal. Much of it is highly sensitive. Yet in many practices, particularly smaller offices, the information is still spread across paper files, personal laptops, WhatsApp conversations, Excel spreadsheets and cloud accounts opened without checking where the servers are located.
The relevant framework is Law No. 09-08 on the protection of individuals with regard to the processing of personal data, promulgated by Dahir No. 1-09-15 of 18 February 2009 and published in Official Bulletin No. 5711 of 5 March 2009. It applies to lawyers, sole practitioners and professional law firms. There is no corporate or professional exemption for the Bar.
Your digital visibility must also be organised coherently. A verified profile on AvocatLib's lawyer space, for example, involves the controlled publication of professional information selected by the lawyer. That is quite different from maintaining an improvised client database containing litigation records, medical information or copies of identity documents. The first is a limited visibility channel; the second is a core processing operation for which your practice remains accountable.
Two obligations that operate together
A Moroccan law firm is subject to two cumulative disciplines. The first is the professional duty of confidentiality laid down by Law No. 28-08 regulating the legal profession, particularly its provisions concerning professional secrecy. The second is the protection of personal data under Law No. 09-08 and its implementing Decree No. 2-09-165 of 21 May 2009.
In plain terms, professional secrecy requires you not to reveal protected information. Data protection law requires you to know why you hold that information, on what legal basis, for how long, where it is stored, who can access it and what safeguards prevent loss or unauthorised disclosure. A locked archive room may help with both duties. A declaration to the CNDP addresses only the regulatory formality; it does not, by itself, make an insecure office compliant.
What Law 09-08 actually covers inside a law firm
Paper files, Excel sheets and case-management software
Article 1 of Law No. 09-08 defines personal data broadly as information, of whatever nature and regardless of its medium, relating to an identified or identifiable natural person. The same article defines processing as any operation or set of operations performed upon personal data, whether or not by automatic means. Collection, recording, organisation, storage, adaptation, consultation, communication, blocking, erasure and destruction all fall within that concept.
Practical consequence: a client list saved in Excel is processing, but so is an organised paper filing system indexed by client name or case number. The absence of specialist software does not take the file outside Law No. 09-08.
Article 2 determines the material and territorial scope of the statute. Subject to the exclusions provided by the law, it covers automated processing and non-automated processing of data contained, or intended to be contained, in an organised file. A sole practitioner in Agadir who keeps indexed client files is therefore concerned in the same way as a multi-partner business law firm in Casablanca. The scale of the practice affects the proportionality of the safeguards, not whether the law applies.
The lawyer as data controller
Article 1 also defines the data controller as the natural or legal person who determines the purposes and means of processing. In a sole practice, the lawyer will normally be the controller. In a professional law firm, the entity may be the controller, represented operationally by its managing partner. Where partners independently determine how separate client portfolios are handled, the allocation must be examined rather than assumed.
This is the practical meaning of the expression responsable du traitement des données du cabinet d'avocat. Liability cannot simply be transferred to the IT technician, accountant or software supplier. A hosting provider may be a processor, but the practice still decides why client data are collected and how they are used.
Partners should record this allocation in their internal governance documents. The point becomes critical when a partner leaves, a professional company is dissolved or two former associates disagree over access to archived matters. A dispute that begins as a question of client ownership can quickly become an unauthorised access or disclosure issue.
Sensitive data are routine in legal practice
Under Article 1, sensitive data include information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership and data concerning health or sex life. The statute also imposes a stricter regime on other particularly protected categories, including data relating to offences, convictions and security measures.
A criminal practice in Tangier will process prosecution records, custody information and convictions. A personal injury lawyer will hold medical reports. A family lawyer in Fez may retain information concerning children, filiation, health and intimate family circumstances. An employment practice may receive trade-union information and medical certificates. These are not marginal exceptions. They form part of the normal work of many chambers.
Article 3 requires personal data to be processed fairly and lawfully, collected for specified, explicit and legitimate purposes, adequate and not excessive, accurate and retained no longer than necessary. That article should guide the opening of every file. Keeping a complete copy of a client's telephone merely because it is technically easy, for example, is difficult to reconcile with the principle of proportionality.
CNDP declaration or prior authorisation: choosing the correct procedure
Ordinary processing and the prior declaration
Article 12 of Law No. 09-08 establishes the prior declaration mechanism for processing operations that are not subject to a different statutory regime. For a legal practice, an ordinary client-management file containing identity details, contact information, billing records and information relating to routine civil or commercial instructions will generally begin with an analysis of whether a declaration is sufficient.
The declaration is submitted to the Commission Nationale de contrôle de la protection des Données à caractère Personnel. The file should identify the controller, processing purposes, categories of persons and data, recipients, retention periods, security arrangements and any intended transfer abroad. The implementing procedures are specified by Decree No. 2-09-165.
Do not treat the filing description as a generic administrative phrase. If the declared purpose is merely “client management” while the firm actually maintains criminal, medical and employment litigation databases, the description may be materially incomplete. A Rabat practice working in medical liability discovered precisely this problem after describing its activity too narrowly: the data inventory revealed health reports, disability assessments and hospital records that required a separate legal analysis.
When prior authorisation is required
The editorial shorthand sometimes used by practitioners—that Article 16 alone authorises all sensitive-data processing—is unsafe. Articles 12 to 23 must be read together, especially the provisions identifying processing subject to prior authorisation and the restrictions applicable to sensitive information. The applicable CNDP form depends on the data, purpose and statutory basis, not merely on the title given to the file by the firm.
Processing concerning health, offences or criminal convictions, national identity identifiers or other specially protected information may require prior authorisation rather than a simple declaration. Consequently, criminal, medical liability and some family-law practices should not submit a generic declaration without mapping their data first. The CNDP can ask for the legal basis, categories of recipients, security controls and justification for retaining each category.
Practitioner's note: before filing, separate your processing operations. Client intake, litigation management, accounting, payroll and website enquiries do not necessarily have the same purpose, legal basis, recipients or retention period. One vague declaration is not always better than several accurate formalities.
The CNDP does not advertise a statutory professional fee for submitting the standard formality. If the work is handled internally, the direct filing cost is therefore ordinarily nil, subject to any change in official procedure. External compliance assistance for a modest practice commonly represents approximately MAD 3,000 to MAD 8,000, while a complex multi-office audit can cost more. Processing time is variable. Four to eight weeks is a sensible operational allowance for a properly prepared authorisation file, but it is not a guaranteed legal deadline and requests for clarification can extend it.
Exemptions are narrow
The exclusion for activities that are exclusively personal or domestic does not cover professional client files. Nor does the small size of the office create an exemption. Likewise, the client's decision to send documents voluntarily does not eliminate the practice's duties of information, security and purpose limitation.
For public professional visibility, controlling the quantity of information collected makes compliance easier. Creating a professional profile through AvocatLib's registration page can be documented as a limited external channel containing professional details chosen for publication. It should never be used to publish client names, case outcomes capable of identifying parties or material protected by Law No. 28-08. Visibility remains subject to the profession's rules against solicitation, improper advertising and comparative claims.
The processing register and your internal evidence file
Why documentation matters even after filing
Law No. 09-08 does not reproduce the GDPR's modern, stand-alone record-of-processing obligation in identical language. It would therefore be inaccurate to claim that Article 24 expressly creates the same register for every Moroccan controller. Article 24 concerns the CNDP's own functions. Nevertheless, the information required for declarations and authorisations, combined with the duties arising from Articles 3, 5, 23 and the security provisions of the statute, makes internal documentation practically indispensable.
If the CNDP asks how your firm complies, a dated processing register is the most efficient answer. It demonstrates that the declaration corresponds to what happens in the office. It also exposes gaps before they become incidents: a former trainee whose account remains active, a Google Drive folder open to everyone, or archived pleadings that should have been destroyed.
What the law firm's register should contain
A useful registre de traitement des données du cabinet juridique au Maroc can be maintained in a secured spreadsheet. For each processing operation, record:
- The purpose: client intake, case management, billing, conflict checks, payroll, recruitment, website enquiries or professional appointments.
- The persons concerned: clients, opponents, witnesses, experts, employees, trainees, suppliers and professional contacts.
- The data categories: identity, CNIE, contact details, banking information, procedural documents, health data, criminal information and employment records.
- The legal basis and formality: declaration receipt, CNDP authorisation, statutory duty, contractual necessity or documented consent where consent is genuinely appropriate.
- Recipients and access rights: responsible partner, assigned associate, secretary, accountant, bailiff, expert or correspondent counsel.
- Hosting and transfers: office server, Moroccan data centre, foreign SaaS platform, email service and backup location.
- Retention and destruction: active-file period, archive period, legal justification and secure destruction method.
- Security: encryption, multi-factor authentication, access logs, locked cabinets, backup tests and incident response.
Record contact channels as well. If a prospect reaches you through an AvocatLib profile, your register should distinguish the initial professional enquiry from the client file created after you accept the instruction. Once medical evidence, a CNIE copy or pleadings are transferred into your own systems, those materials fall under the firm's processing operation and cannot be treated as mere directory information.
Retention is not a universal seven-year rule
Article 3 of Law No. 09-08 requires data not to be kept in an identifiable form beyond the period necessary for the stated purpose. Moroccan law does not prescribe one universal retention period for every lawyer's file. The period must be built around limitation rules, professional duties, tax requirements, pending enforcement and the possibility of a fee or liability dispute.
Attention, however: Article 387 of the Code of Obligations and Contracts does not establish a general five-year civil limitation period. It lays down a general period of fifteen years, subject to special statutory periods. Article 5 of the Commercial Code, by contrast, provides a five-year limitation period for obligations arising between merchants in connection with their commercial activities, unless a special rule applies.
A blanket “seven years after closure” policy may therefore be too short for some civil files and excessive for other data. Adopt a retention schedule by matter category. Keep a short administrative record of destroyed files—matter number, destruction date and authority for destruction—without preserving the sensitive contents themselves.
Professional secrecy and data protection are complementary
The protection afforded by Law 28-08
Law No. 28-08 regulating the legal profession imposes professional secrecy on the lawyer, notably through the provisions commonly cited around Articles 36 and 37 concerning confidentiality and the protection of information learned in practice. The exact provision must be read with the profession's unified internal rules and the disciplinary practice of the competent Bar Council.
Professional secrecy is not simply a contractual promise. It is a core professional obligation, enforceable before the Conseil de l'Ordre and relevant in criminal and civil proceedings. It protects consultations, correspondence, defence strategy and information entrusted to counsel. The fact that a client has exercised access rights under data protection law does not entitle an opposing party to obtain privileged material.
A CNDP inspection does not abolish privilege
The CNDP's supervisory powers do not create an unrestricted right to read the substance of privileged case files. Equally, a lawyer cannot invoke secrecy to refuse every question concerning whether processing has been declared, how access is controlled or where data are hosted. The correct approach is to distinguish the content of legal advice from evidence about the organisation of processing.
If a control measure risks reaching privileged material, the practice should immediately define the scope, preserve its objections in writing and, where appropriate, involve the Bâtonnier. Do not obstruct the authority, but do not surrender entire case files merely because an IT or compliance question has been raised. In the absence of abundant published Cour de cassation case law specifically reconciling CNDP inspections with lawyers' professional secrecy, careful procedural documentation is essential.
Information provided to clients
Article 5 of Law No. 09-08 requires the person concerned to receive prescribed information when data are collected, including the identity of the controller, processing purposes, recipients, whether replies are compulsory, the consequences of non-response and the existence of rights of access and rectification. The wording must be adapted where data are obtained indirectly or where a statutory exception applies.
The simplest professional solution is a data protection clause in the fee agreement, supplemented by a privacy notice on the firm's website and a concise notice on electronic intake forms. The clause should not seek unlimited consent to every conceivable use. It should identify the actual purposes: conflict checks, management of the instruction, procedural communications, invoicing, legal archiving and compliance with professional duties.
Article 9 protects the right to object in the circumstances defined by the statute, while the preceding provisions regulate access and rectification. Your internal procedure should identify who answers a request, how the requester's identity is verified, how third-party and privileged information is separated and when the response is recorded.
A five-step CNDP compliance plan for a Moroccan law firm
Step 1: map the information before drafting forms
Set aside one or two working days for a medium-sized office. Follow the data from reception to archive: telephone enquiry, appointment, conflict check, fee agreement, CNIE copy, pleadings, email, expert report, invoice and destruction. Include WhatsApp, personal telephones, USB drives and paper notebooks. These informal channels are usually where the audit becomes uncomfortable.
List every person who can see a file. A trainee printing a pleading, a secretary receiving medical documents and an external accountant processing invoices all create access points. Not everyone is legally a processor: staff acting under the direct authority of the controller are generally authorised users, while an independent service provider processing data on the firm's instructions may qualify as a processor. Contracts and access controls should reflect the real relationship.
Step 2: identify the CNDP formality
Separate ordinary client administration from sensitive litigation data and transfers abroad. Prepare the purpose, data categories, recipients, retention periods and security measures before opening the CNDP form. For an authorisation request, explain why the sensitive information is necessary and why a less intrusive alternative would not enable you to conduct the instruction.
Keep the submission, attachments, receipt, CNDP correspondence and final decision in a dedicated compliance file. A declaration number copied into a fee agreement is not enough if nobody can locate the approved scope three years later.
Step 3: revise contracts and public notices
Update fee agreements, trainee agreements, employment documents, collaboration arrangements, supplier contracts, website notices and electronic forms. Clauses should cover confidentiality, authorised instructions, return or deletion of information, incident notification and restrictions on subcontracting.
Review public-facing tools separately. A controlled professional presence through AvocatLib, Google Business Profile, LinkedIn or the firm's own website should publish only accurate professional information. Do not post testimonials that expose a client relationship, identifiable judgments without a proper legal basis, or comparative claims. Law No. 28-08 and Bar rules continue to prohibit solicitation and communications incompatible with the dignity of the profession.
Step 4: secure physical and digital files
Use individual accounts rather than a shared office password. Activate multi-factor authentication for email and cloud services. Encrypt laptops, test backups and revoke access on the same day a trainee or employee leaves. Sensitive paper files should be stored in locked areas, with keys controlled and archive movements recorded.
For a small practice, basic improvements may cost between MAD 500 and MAD 3,000 for password management, encrypted backup media and essential security tools, excluding hardware and specialist intervention. The declaration itself is not the expensive part. The real cost arises when years of disorganised files must be classified under the pressure of an incident or formal notice.
Step 5: train the people who handle files
A ten-minute warning to “respect confidentiality” is insufficient. Give staff concrete rules: no client files on personal USB drives, no procedural documents sent to the wrong WhatsApp group, no shared cloud link without an expiry date, and no photograph of a hearing list posted online. Repeat the session when tools or personnel change.
Practitioner's note: a proactive regularisation is far easier to defend than silence after a CNDP request. If you discover an old undeclared processing operation, document the discovery, contain the risk and file the appropriate formality without delay.
Foreign cloud services and transfers outside Morocco
Many case-management, email, videoconferencing and document-signature services store information outside Morocco. Articles 43 and 44 of Law No. 09-08 regulate transfers of personal data to foreign States. A transfer cannot be treated as an ordinary technical detail simply because the supplier is established and reputable.
You must identify the actual hosting country, backup locations, support access and subcontractors. Then verify whether the destination offers the required level of protection or whether another statutory mechanism and CNDP formality is needed. Contractual clauses are useful, but they do not automatically replace an authorisation required by Moroccan law.
Ask the provider for its data-processing terms, security certification, breach-notification procedure, deletion commitments and list of subprocessors. If the sales representative cannot tell you where the data are hosted, do not upload criminal, family or medical files while waiting for an answer. A Moroccan hosting solution may simplify the transfer analysis, although local hosting alone does not guarantee security or full compliance.
CNDP controls, criminal exposure and disciplinary risk
What can trigger scrutiny
A control may follow a complaint from a client, former employee, former partner or opposing party. It may also arise after a data leak or as part of a sectoral control programme. Historically, visible CNDP enforcement has often focused on larger companies and public bodies, but Law No. 09-08 does not exclude liberal professions or small practices.
The CNDP can examine formalities, security, information notices, respect for individual rights and international transfers. Depending on the legal basis and stage of the procedure, it may issue observations, require regularisation or refer offences to the competent prosecutorial authorities. Do not assume that every first contact will lead immediately to prosecution. Do not assume, either, that an unanswered formal notice will disappear.
Penalties must be matched to the precise offence
The criminal provisions appear in the final part of Law No. 09-08 and distinguish several offences: unlawful processing, failure to comply with required formalities, misuse of data, interference with individual rights, inadequate security and unlawful transfers. Depending on the offence, the statute provides fines that may range from tens of thousands to several hundred thousand dirhams and, for certain conduct, imprisonment from three months to one year. Repeat offending and liability of legal entities may alter the exposure.
It is unsafe to quote “Articles 64 and following” as though every omission automatically carried a MAD 300,000 fine. The charging provision, material facts and status of the offender must be identified. A lawyer responding to a CNDP notice should therefore request the legal basis, preserve evidence of existing safeguards and regularise what can be corrected without making inaccurate admissions.
The separate disciplinary dimension
A leak of client information, reckless cloud configuration or refusal to secure archives may also amount to a professional breach. The Bâtonnier and Conseil de l'Ordre assess disciplinary responsibility independently of the criminal court. An acquittal on a narrowly defined data offence does not necessarily exclude a finding that the lawyer failed to preserve professional secrecy or the dignity and prudence required by the profession.
Digital restraint reduces the attack surface. A structured professional profile on AvocatLib, rather than a collection of uncontrolled enquiry forms and public spreadsheets, can form part of that approach. It does not replace CNDP compliance, and it cannot be presented as a guarantee against an incident. It simply helps separate public professional information from confidential client records.
Three situations encountered in Moroccan practices
A criminal practice in Tangier
The practice receives custody records, copies of CNIE documents, criminal records, witness details and medical certificates. A simple “customer management” declaration does not adequately describe the processing. The partners should map each category, determine the authorisation required, restrict access by matter and prevent criminal documents from being copied into general contact-management software.
Paper files should not remain in an open reception area. Digital folders should be accessible only to the assigned team. When corresponding counsel or an expert receives a document, the practice should record the purpose, legal necessity and recipient. The communication must be limited to what is required for the defence.
A family lawyer in Fez
The lawyer represents a parent in proceedings involving children. The file contains school records, medical information, family photographs and allegations concerning the other parent. The privacy notice must account for the fact that information concerns several persons, some of whom are not the contracting client.
Children's data require particular restraint. Avoid copying an entire school or medical history when only one certificate is relevant. When the file closes, separate procedural originals that must be returned from copies retained for justified archival purposes. Any online publication about the case, even presented as an educational success story, must be checked for indirect identification.
A Casablanca firm using a shared CRM
Six partners share a cloud-based CRM hosted abroad. Every trainee can view every contact and upload attachments. The firm has not checked the hosting country or deactivated the accounts of two former associates. This is not merely an IT inconvenience. It raises purpose limitation, access control, processor-contract and international-transfer issues.
The solution is not necessarily to abandon the CRM. The firm should define roles, remove unnecessary attachments, restrict permissions, verify the provider and complete the required CNDP formalities. For public visibility, partners may maintain individual professional profiles through AvocatLib registration rather than turning a confidential CRM into a marketing database. Each profile remains limited to professional information, while common client data stay in the secured practice system.
From regulatory burden to professional discipline
What you should do tomorrow morning
Begin with five actions: inventory your files, identify sensitive data, verify your CNDP declarations and authorisations, review foreign hosting, and close obsolete access accounts. Then add the privacy clause to new fee agreements and adopt a retention schedule based on the actual limitation period applicable to each type of matter.
Compliance is not a one-off certificate. It is closer to accounting discipline: the register must be updated, departures must trigger access revocation, backups must be tested and new software must be reviewed before client data are uploaded. Corporate clients increasingly ask their external counsel where documents are hosted and who can access them. A clear answer strengthens confidence without making promotional claims.
A controlled professional presence
While regularising your data practices, review how future clients find you. A verified profile on AvocatLib can make your city, Bar and practice areas accessible without resorting to prohibited solicitation or comparative advertising. You can also review the platform's lawyer-space features and organise visibility across Moroccan Bar locations, from Casablanca and Rabat to Tangier, Marrakech, Fez and Agadir.
The objective is modest but sound: publish professional information deliberately, keep client information confidential, and be able to prove that distinction if the CNDP, the Bâtonnier or a client asks. That is what modern management of a Moroccan law firm now requires.

