Regulation · CNDP · July 2026

How do you file a CNDP declaration? Forms, timelines, and the trap most companies miss

The direct answer: download the current form from cndp.ma (F211 normal, F214 simplified), attach proof of the signatory’s authority, and file — the receipt arrives within 24 hours. Sensitive data needs prior authorization instead, and foreign hosting needs its own separate transfer request.

Article

The short answer: for ordinary processing — customer management, payroll, HR, classic prospecting — you download the current declaration form from the CNDP’s site (the normal declaration F211, or the simplified F214 when your activity matches a model the CNDP has already framed by decision), attach the document proving the signatory can bind your company, and file it. The CNDP issues the receipt within 24 hours, and that receipt is what lets you lawfully run the processing.

The timelines that matter

Two clocks run after a declaration. The receipt comes within a day — but the CNDP keeps an 8-day window to reclassify your activity into the stricter prior-authorization regime if it judges the processing manifestly risky for privacy. Build both into your launch planning: the receipt is fast; certainty takes a week.

When you need authorization instead

Processing involving sensitive data — health, biometric or genetic data, opinions and beliefs, offenses — or other high-risk configurations requires a prior authorization (form F112, or F113 under a framing decision) before anything starts. The file is heavier: evidence that data subjects were informed, consent extracts where relevant, subcontracting clauses covering security. And the timeline changes scale — practitioners plan for weeks up to two months, an incomplete file stops the clock, and silence from the Commission is treated as refusal, not consent. An authorization is prepared ahead of a deadline, never the night before.

The trap: transfers are a separate filing

Here is the mistake we see most: assuming the declaration “covers” cloud hosting abroad. It does not. Sending personal data outside Morocco — foreign cloud, SaaS with servers abroad, offshore support — is governed by Articles 43–44 and requires its own transfer request (F118), which the CNDP only grants once the underlying processing has itself been declared or authorized. Two formalities, in order — and if EU residents’ data is involved, the GDPR adds its own transfer layer on top.

Practical hygiene

Always download the form in force from cndp.ma rather than reusing an old copy — the Commission updates them. Describe your purpose exactly as you practice it; a mismatch invalidates the receipt in a later control. And notify the CNDP of any changes without delay.

If assembling the file feels heavier than expected, that is usually a sign the underlying data map needs work first — which is what our free Governance Readiness Assessment surfaces in minutes. Forms and procedures cited as in force at the time of writing; this is general information, not legal advice — the legal qualification of your processing belongs with Moroccan counsel.

← All articles

Talk to us about this topic

Book a discovery call — in French, Arabic, or English — and we’ll map this to your organization.

Get FutureRoc in