Skip to Content
HomeConsultingESG / CSRGDPR Governance / 09-08
Triple ISO firm+70 consultantsContractualised resultsResponse within 48 hours
The context

Personal data, a legal responsibility

Law 09-08 (CNDP) imposes obligations on the processing of personal data, with penalties at stake. The GDPR adds to this for European flows.

What you gain

  • Compliance with law 09-08 (CNDP) & GDPR
  • Mapping of processing activities
  • Register and declarations CNDP
  • Reduction of penalty risk
  • Trust from clients and partners
  • Sustainable Data Governance

Our Approach

1
Phase 1

Mapping

Inventory of data processing.

2
Phase 2

Gap Analysis

Compliance vs legal obligations.

3
Phase 3

Compliance Implementation

Register, notices, CNDP declarations.

4
Phase 4

Governance

Policies, training, monitoring.

Your Deliverables

Processing Register

Compliant inventory.

CNDP Declarations

Declaration/authorisation files.

Policies & notices

Compliant documents.

Relevant sectors

IT & OffshoringBanking & FinanceHealth & PharmacyCommerce & RetailServices
ISO 9001 CertifiedISO 37301 CertifiedPECBIASSC Lean Six SigmaIAF · IAS — International Accreditation ServiceResponsible SME Label

Frequently Asked Questions

Is law 09-08 mandatory?+
Yes, for any organisation processing personal data in Morocco, with CNDP declaration/authorisation.
GDPR or 09-08?+
Both if you process data of EU residents. We cover both frameworks.
What is TargetUp's 'Governance & GDPR' mission?+
It is a comprehensive support for compliance with law 09-08 (CNDP) and GDPR. TargetUp maps your personal data processing, measures gaps with your legal obligations, builds your processing register, and prepares your CNDP declarations. The mission also establishes sustainable data governance: policies, legal notices, training, and monitoring.
Which organisations does this data governance service target?+
Any organisation that processes personal data in Morocco, and those whose flows concern residents of the European Union — in which case the dual framework of law 09-08 + GDPR applies. TargetUp primarily serves the IT & offshoring, banking & finance, health & pharmacy, commerce & retail, and services sectors, both in Morocco and in French-speaking Africa.
Why implement GDPR compliance now?+
Law 09-08 requires declarations and authorisations with the CNDP, with penalties for non-compliance. Beyond legal risks, compliance has become a trust criterion demanded by clients, partners, and contractors, particularly regarding European flows. Acting proactively avoids formal notices and secures your tenders and partnerships.
How does the compliance process actually work?+
In four phases. Phase 1: mapping and inventory of your data processing activities. Phase 2: gap analysis between your practices and your legal obligations. Phase 3: compliance — register, notices and CNDP declarations. Phase 4: governance — policies, training and monitoring. You will benefit from a dedicated consultant and a response within 48 hours of your diagnostic request.
What concrete deliverables do we receive at the end of the mission?+
Three operational and directly usable deliverables: a compliant processing register, the CNDP declaration or authorisation files, and your drafted policies and legal notices. These documents serve as proof of your compliance in the event of a CNDP audit and form the sustainable foundation of your data governance.
Do we need to have already mapped our data or have a DPO to start?+
No. Mapping is precisely the first phase of the mission: TargetUp conducts the inventory of your processing activities based on your actual processes, without any technical prerequisites on your part. You do not need an existing register or a DPO in place to begin; the support will guide you step by step to compliance.
What distinguishes TargetUp's GDPR support?+
TargetUp is a triple ISO certified firm — ISO 9001, 21001 and 37301 — the latter standard specifically concerning compliance management systems. This expertise ensures a structured method and contractualised results. Data governance is part of our ESG/CSR and compliance offering, ensuring long-term compliance rather than a one-off file.
Tailored support
On quotation
Free opportunity diagnostic
  • Response within 48 hours
  • Dedicated consultant
  • Quotation & schedule
Book a slot · 30 min (B2B diagnostic)
or write to us
✓ Automatically detected from the page
Protected data · CNDP
★★★★★
The CNDP compliance has helped us avoid a major risk and reassured our clients.
YK
DPO
Service centre · Rabat

Secure your personal data

Free diagnostic to map your levers.

Start