<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Personal Data &#8211; Neo Expertise</title>
	<atom:link href="https://neoexpertise.net/category/cndp/personal-data/feed/" rel="self" type="application/rss+xml" />
	<link>https://neoexpertise.net</link>
	<description>Expert Business Advisory &#38; Accounting Firm in Morocco</description>
	<lastBuildDate>Fri, 09 Jan 2026 09:47:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://neoexpertise.net/wp-content/uploads/2026/04/cropped-last-vr-ornage-logo-ezgif.com-gif-to-webp-converter-32x32.webp</url>
	<title>Personal Data &#8211; Neo Expertise</title>
	<link>https://neoexpertise.net</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>What Are Sensitive Personal Data Under Law 09-08?</title>
		<link>https://neoexpertise.net/what-are-sensitive-personal-data-under-law-09-08/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-are-sensitive-personal-data-under-law-09-08</link>
		
		<dc:creator><![CDATA[Brahim Rami ,Member of institute of chartered accountants in Morocco]]></dc:creator>
		<pubDate>Fri, 09 Jan 2026 09:47:40 +0000</pubDate>
				<category><![CDATA[CNDP]]></category>
		<category><![CDATA[Personal Data]]></category>
		<guid isPermaLink="false">https://neoexpertise.net/?p=3382</guid>

					<description><![CDATA[Under Moroccan Law 09-08, sensitive personal data refers to specific categories of information whose processing presents a higher risk to individuals’ fundamental rights and therefore requires stricter legal control, often including prior CNDP authorization.Any company processing such data in Morocco must proceed with particular caution and comply with enhanced obligations supervised by the CNDP. Legal [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Under Moroccan <a href="https://neoexpertise.net/law-09-08-explained-moroccos-data-protection-law-for-businesses/">Law 09-08</a>, sensitive <a href="https://neoexpertise.net/personal-data-under-moroccan-law/">personal data</a> refers to specific categories of information whose processing presents a higher risk to individuals’ fundamental rights and therefore requires stricter legal control, often including prior <a href="https://neoexpertise.net/cndp-in-morocco/">CNDP</a> authorization.</strong><br>Any company processing such data in Morocco must proceed with particular caution and comply with enhanced obligations supervised by the CNDP.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<div class="wp-block-rank-math-toc-block has-palette-color-7-background-color has-background" id="rank-math-toc"><h2>Table of Contents</h2><nav><ul><li><a href="#legal-basis-under-moroccan-law">Legal basis under Moroccan law</a></li><li><a href="#what-qualifies-as-sensitive-personal-data">What qualifies as sensitive personal data?</a></li><li><a href="#health-and-medical-data">Health and medical data</a></li><li><a href="#biometric-and-genetic-data">Biometric and genetic data</a></li><li><a href="#political-religious-and-philosophical-data">Political, religious, and philosophical data</a></li><li><a href="#criminal-records-and-security-measures">Criminal records and security measures</a></li><li><a href="#employee-data-when-does-it-become-sensitive">Employee data: when does it become sensitive?</a></li><li><a href="#when-is-cndp-authorization-required">When is CNDP authorization required?</a></li><li><a href="#common-business-activities-involving-sensitive-data">Common business activities involving sensitive data</a></li><li><a href="#risks-of-improper-handling-of-sensitive-data">Risks of improper handling of sensitive data</a></li><li><a href="#frequently-asked-questions">Frequently Asked Questions</a><ul><li><a href="#is-all-employee-data-considered-sensitive-no-only-specific-categories-such-as-health-or-disciplinary-data-are-considered-sensitive">Is all employee data considered sensitive?</a></li><li><a href="#does-consent-remove-the-need-for-authorization-no-consent-alone-does-not-generally-replace-cndp-authorization-for-sensitive-data">Does consent remove the need for authorization?</a></li><li><a href="#are-biometric-access-systems-allowed-yes-but-they-typically-require-prior-cndp-authorization">Are biometric access systems allowed?</a></li></ul></li><li><a href="#key-takeaway">Key takeaway</a></li></ul></nav></div>



<h2 class="wp-block-heading" id="legal-basis-under-moroccan-law">Legal basis under Moroccan law</h2>



<p class="wp-block-paragraph">The concept of sensitive personal data is defined by <strong>Law 09-08 on the protection of individuals with regard to the processing of personal data</strong>.</p>



<p class="wp-block-paragraph">The law recognizes that certain types of information, by their nature, may seriously affect privacy, dignity, or individual freedoms if misused.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="what-qualifies-as-sensitive-personal-data">What qualifies as sensitive personal data?</h2>



<p class="wp-block-paragraph">Under Law 09-08, sensitive personal data includes information that reveals or relates to:</p>



<ul class="wp-block-list">
<li class="">health and medical data</li>



<li class="">biometric and genetic data</li>



<li class="">racial or ethnic origin</li>



<li class="">political opinions</li>



<li class="">religious or philosophical beliefs</li>



<li class="">trade union membership</li>



<li class="">data relating to criminal convictions or security measures</li>
</ul>



<p class="wp-block-paragraph">These categories are interpreted <strong>broadly</strong> by the CNDP.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="health-and-medical-data">Health and medical data</h2>



<p class="wp-block-paragraph">Health data is one of the most strictly regulated categories.</p>



<p class="wp-block-paragraph">This includes:</p>



<ul class="wp-block-list">
<li class="">medical records</li>



<li class="">laboratory results</li>



<li class="">medical certificates</li>



<li class="">disability information</li>



<li class="">health insurance data</li>
</ul>



<p class="wp-block-paragraph">Processing health data almost always requires <strong>prior <a href="https://neoexpertise.net/cndp-declaration-vs-cndp-authorization-key-legal-differences/">CNDP authorization</a></strong>, except in very limited circumstances.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="biometric-and-genetic-data">Biometric and genetic data</h2>



<p class="wp-block-paragraph">Biometric and genetic data are considered highly sensitive.</p>



<p class="wp-block-paragraph">Examples include:</p>



<ul class="wp-block-list">
<li class="">fingerprints</li>



<li class="">facial recognition data</li>



<li class="">DNA data</li>



<li class="">retinal or iris scans</li>
</ul>



<p class="wp-block-paragraph">Their use is subject to heightened scrutiny due to the irreversible nature of biometric identifiers.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="political-religious-and-philosophical-data">Political, religious, and philosophical data</h2>



<p class="wp-block-paragraph">Data revealing:</p>



<ul class="wp-block-list">
<li class="">political affiliations or opinions</li>



<li class="">religious beliefs or practices</li>



<li class="">philosophical convictions</li>
</ul>



<p class="wp-block-paragraph">is classified as sensitive because of the potential impact on individual freedoms and non-discrimination principles.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="criminal-records-and-security-measures">Criminal records and security measures</h2>



<p class="wp-block-paragraph">Information relating to:</p>



<ul class="wp-block-list">
<li class="">criminal convictions</li>



<li class="">ongoing investigations</li>



<li class="">judicial sanctions</li>



<li class="">security or surveillance measures</li>
</ul>



<p class="wp-block-paragraph">falls squarely within the sensitive data category and is subject to strict authorization requirements.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="employee-data-when-does-it-become-sensitive">Employee data: when does it become sensitive?</h2>



<p class="wp-block-paragraph">Not all employee data is sensitive, but <a href="https://neoexpertise.net/hr-practices-managing-workplace-conflicts-morocco/">HR</a> data becomes sensitive when it includes:</p>



<ul class="wp-block-list">
<li class="">medical leave records</li>



<li class="">disciplinary or criminal matters</li>



<li class="">biometric access controls</li>



<li class="">union membership</li>
</ul>



<p class="wp-block-paragraph">Employers must carefully assess HR processing activities.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="when-is-cndp-authorization-required">When is CNDP authorization required?</h2>



<p class="wp-block-paragraph">As a general rule, <strong>processing sensitive personal data requires prior CNDP authorization</strong> before any activity begins.</p>



<p class="wp-block-paragraph">This applies regardless of:</p>



<ul class="wp-block-list">
<li class="">company size</li>



<li class="">sector of activity</li>



<li class="">whether the company is Moroccan or foreign</li>
</ul>



<p class="wp-block-paragraph">Starting processing without authorization constitutes a legal violation.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="common-business-activities-involving-sensitive-data">Common business activities involving sensitive data</h2>



<p class="wp-block-paragraph">Sensitive data is frequently processed in:</p>



<ul class="wp-block-list">
<li class="">healthcare and medical services</li>



<li class="">insurance and social protection</li>



<li class="">call centers with call recording involving sensitive content</li>



<li class="">HR and payroll systems</li>



<li class="">access control systems using biometrics</li>



<li class="">compliance and background-check services</li>
</ul>



<p class="wp-block-paragraph">These activities require careful legal qualification.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="risks-of-improper-handling-of-sensitive-data">Risks of improper handling of sensitive data</h2>



<p class="wp-block-paragraph">Improper processing may result in:</p>



<ul class="wp-block-list">
<li class="">CNDP warnings or enforcement actions</li>



<li class="">suspension or prohibition of processing</li>



<li class="">criminal liability for company officers</li>



<li class="">significant reputational damage</li>
</ul>



<p class="wp-block-paragraph">Sensitive data violations are treated more seriously than standard compliance breaches.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="frequently-asked-questions">Frequently Asked Questions</h2>



<h3 class="wp-block-heading" id="is-all-employee-data-considered-sensitive-no-only-specific-categories-such-as-health-or-disciplinary-data-are-considered-sensitive"><strong>Is all employee data considered sensitive?</strong></h3>



<p id="is-all-employee-data-considered-sensitive-no-only-specific-categories-such-as-health-or-disciplinary-data-are-considered-sensitive" class="wp-block-paragraph">No. Only specific categories, such as health or disciplinary data, are considered sensitive.</p>



<h3 class="wp-block-heading" id="does-consent-remove-the-need-for-authorization-no-consent-alone-does-not-generally-replace-cndp-authorization-for-sensitive-data"><strong>Does consent remove the need for authorization?</strong></h3>



<p id="does-consent-remove-the-need-for-authorization-no-consent-alone-does-not-generally-replace-cndp-authorization-for-sensitive-data" class="wp-block-paragraph">No. Consent alone does not generally replace CNDP authorization for sensitive data.</p>



<h3 class="wp-block-heading" id="are-biometric-access-systems-allowed-yes-but-they-typically-require-prior-cndp-authorization"><strong>Are biometric access systems allowed?</strong></h3>



<p id="are-biometric-access-systems-allowed-yes-but-they-typically-require-prior-cndp-authorization" class="wp-block-paragraph">Yes, but they typically require prior CNDP authorization.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading" id="key-takeaway">Key takeaway</h2>



<p class="wp-block-paragraph"><strong>Sensitive personal data under Law 09-08 is subject to strict legal protection and enhanced regulatory control.</strong><br>Any business processing such data must assess its obligations carefully and obtain CNDP authorization where required.</p>



<p class="wp-block-paragraph">Correct classification of sensitive data is essential to lawful and secure operations in Morocco.</p>



<div class="nfd-p-card-md nfd-gap-xl nfd-shadow-xs nfd-rounded is-style-nfd-theme-light wp-block-group is-content-justification-space-between is-layout-flex wp-container-core-group-is-layout-18f3c2fd wp-block-group-is-layout-flex">
<div class="nfd-gap-md wp-block-group is-layout-flex wp-block-group-is-layout-flex">
<figure class="is-style-rounded wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="381" height="381" loading="lazy" src="https://neoexpertise.net/wp-content/uploads/2025/09/cropped_circle_image.png" alt="brahim rami" class="wp-image-3232" style="object-fit:cover;width:133px;height:auto" srcset="https://neoexpertise.net/wp-content/uploads/2025/09/cropped_circle_image.png 381w, https://neoexpertise.net/wp-content/uploads/2025/09/cropped_circle_image-300x300.png 300w, https://neoexpertise.net/wp-content/uploads/2025/09/cropped_circle_image-150x150.png 150w" sizes="auto, (max-width: 381px) 100vw, 381px" /></figure>



<div class="nfd-gap-0 wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-1f26014c wp-block-group-is-layout-flex">
<p class="nfd-text-md wp-block-paragraph" style="font-style:normal;font-weight:600"><strong>Brahim Rami</strong> | <em>Member of institute of chartered accountants in Morocco</em></p>



<p class="nfd-text-base nfd-text-faded has-text-align-left wp-block-paragraph">He is a CPA and tax advisor, founder of NeoExpertise.net, a Legal and Tax firm helping foreign companies with business setup, <a href="https://neoexpertise.net/due-diligence-checklist-for-moroccan-leasehold-property/">due diligence</a>, payroll, and tax compliance in Morocco and Africa.</p>
</div>
</div>



<div class="wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex">
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://neoexpertise.net/contact/" target="_blank" rel="noreferrer noopener">Book Your Free Consultation</a></div>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
