Atlas layer / data bordersMap before collection
Atlas / Data border map

Discovery—not a compliance verdict

Know which information crosses which border.

Before screens and databases are designed, identify the people represented by the data, the reason each field exists, every system and vendor that touches it, and who has authority to make the final privacy decisions.

Six coordinates

Draw the data route.

This working map helps technical discovery expose responsibilities. It is not a substitute for advice from the CNDP, qualified Moroccan counsel, or the client’s designated privacy lead.

1. People

List customers, staff, applicants, suppliers, children, patients, or other individuals represented. Sensitivity and consequence vary by context.

2. Purpose

Give each collection a defined business reason. Avoid gathering information merely because a field might be useful later.

3. Location

Record where browsers, applications, backups, logs, analytics, support tools, and integrations store or transmit information.

4. Access

Name roles, administrators, vendors, and support personnel who can view, change, export, or delete records. Include emergency access.

5. Lifecycle

Define creation, correction, retention, archival, deletion, restoration, and evidence requirements—including what backups can realistically do.

6. Response

Identify the people responsible for individual requests, vendor failures, security events, incorrect records, and decisions that require escalation.

Remote-delivery boundary

Cross-border questions must be answered deliberately.

Faith Forge Labs is a United States-based provider. A Morocco-facing engagement therefore needs an explicit review of whether the provider or any selected vendor would receive or access personal data, how that access is controlled, which locations are used, what agreements or authorizations may apply, and who is qualified to make those determinations.

The technical design can support approved decisions through data minimization, role-based access, encryption, logs, deletion workflows, vendor configuration, and documented controls. It cannot independently declare the organization compliant or decide which legal mechanism applies.

Questions for the client’s reviewer

  • Which processing activities fall within Morocco’s personal-data framework and who is responsible for them?
  • What notices, permissions, filings, authorizations, or contracts apply to the actual purpose and vendors?
  • May information be hosted or accessed outside Morocco, and under what approved conditions?
  • How must people exercise access, correction, objection, or other applicable rights?
  • What retention, security, and incident-response evidence must the organization preserve?
Implementation checkpoint: the approved data map, vendor list, reviewer decision, and responsible owner should be recorded before production data is introduced.

Primary source

Review current CNDP material.

The Commission Nationale de contrôle de la protection des Données à caractère Personnel publishes Morocco’s official privacy materials. Requirements can change and their application depends on the actual project.

Bring the current reality

Map one data journey before discussing features.

Open the project canvas404-939-0637faithforgelabsllc@gmail.com