Legal and compliance · 9 min read
·Published August 1, 2026
Customer Data Protection: What the CNDP Expects From Your Agency
Scanned passports, driving licenses, bank cards: your agency collects sensitive personal data on every rental. Here are the CNDP compliance basics to respect to protect your customers and your agency.

Direct answer
To meet CNDP obligations in Morocco, a rental agency must clearly inform its customers of how their personal data is used, secure its storage against any unauthorized access, limit its retention to a justified duration, and ensure that only authorized staff access it within the strict scope of their duties.
A rental agency handles identity documents, driving licenses, and banking information daily, a volume of sensitive personal data often managed without deep reflection on the legal obligations that govern its collection and retention. This guide details the practical compliance basics to put in place.
Why this topic deserves the attention of every agency, not just large companies
Many agency operators think personal data protection concerns only large tech companies, whereas any structure that collects passports, licenses, and banking information is directly subject to the obligations of law 09-08 and the CNDP, regardless of its actual size.
This guide translates these obligations into concrete actions applicable immediately in a rental agency, without complex legal jargon, so compliance becomes an operational practice rather than a theoretical concern relegated to the back of your daily priorities.
Clearly informing the customer of how their data is used
The customer must know precisely why you collect their documents, how they will be used, and how long they will be kept, information generally built directly into the rental contract under a dedicated clause, rather than hidden in a separate document the customer never actually reads.
This transparency protects the agency legally and also strengthens customer trust, who perceives serious and responsible management of their sensitive personal information rather than an opaque collection whose final destination and actual use they are totally unaware of.

Securing physical and digital document storage
Paper documents should be kept in a locked space accessible only to authorized staff, while scanned documents deserve password-protected storage, ideally in a dedicated system rather than a simple shared folder accessible to the whole team without particular restriction.
A dedicated management software that natively integrates access controls and encryption of stored data greatly facilitates this security, compared to manual management scattered across several non-centralized physical and digital media.
Limiting data retention to a justified duration
Keep a customer's documents for a reasonable period after the rental ends, generally tied to applicable accounting and tax obligations, rather than keeping them indefinitely without clear justification, a practice that unnecessarily increases risk in the event of a leak or hack of your systems.
Establish a clear deletion policy after this defined period, a process that can be automated in your management system to avoid the gradual accumulation of obsolete data that no longer serves any legitimate purpose for your agency.
Restricting access to genuinely relevant staff
Not all your agents necessarily need access to the entire history of customer files: restrict access according to each employee's actual role, a simple measure that significantly reduces the risk of sensitive personal data being viewed without legitimate reason by an uninvolved team member.
This access restriction also protects your customers against internal misuse, such as an employee curiously browsing a file with no direct connection to the rental in question, a risk often underestimated but very real in a small structure where internal controls sometimes remain informal.
The special case of banking data collected for the deposit
Card information deserves even stricter vigilance than other documents, since unauthorized access could directly facilitate financial fraud: avoid manually writing down full card numbers on an unsecured paper document, a risky practice still too common at some agencies.
Favor a compliant electronic payment system that automatically masks part of the card number, rather than a full manual transcription that needlessly exposes this sensitive information to a risk of leak or unauthorized viewing by a third party.
Handling a possible customer access or deletion request
A customer has the right to request access to their own data or its deletion, subject to applicable legal retention obligations, a request your agency must be able to answer quickly through an organized system rather than a tedious manual search through scattered archives.
Designate a responsible person within your agency to handle this type of request, even an occasional one, so the customer gets a clear and prompt response rather than prolonged silence that could legitimately trigger a formal complaint to the CNDP.
Training your team in basic good practices
Simple but regular training on data protection good practices, such as never leaving a customer document visible on an unattended counter or systematically locking your workstation when stepping away, considerably reduces the risk of incidents linked to everyday negligence rather than genuine malice.
This culture of vigilance, progressively built into the habits of the whole team, costs little to put in place compared to the reputational and financial risk of a data leak becoming public and durably affecting your customers' trust in your agency.
What to do in the event of a data leak or loss
If an incident occurs despite your precautions, a lost USB drive containing document scans for example, act quickly: assess the actual scale of the risk, inform potentially affected customers if necessary, and document the incident along with the corrective measures taken to prevent it from recurring.
This responsiveness, rather than an embarrassed silence hoping the incident goes unnoticed, limits reputational damage and demonstrates a seriousness that can significantly mitigate the consequences if the incident were nonetheless to reach the attention of competent authorities or affected customers.
The link between this compliance and commercial trust
An agency able to clearly explain its data protection policy to a customer who asks the question, an increasingly common profile among international customers aware of these issues, stands out positively from competitors who have never seriously thought about this yet essential question.
This transparency can even become a differentiating commercial argument, particularly to attract a professional or international customer base more demanding on compliance issues than your agency's average traditional local clientele.
Documenting your internal data protection policy
Write a simple internal document that summarizes your policy on customer data collection, storage, retention, and deletion, a reference resource for training new employees and demonstrating your seriousness in the event of an inspection or information request from a competent authority.
This document does not need to be complex or legally dense: a clear, practical page, periodically revised as your tools and processes evolve, is generally enough for a small to medium-sized agency operating in the Moroccan rental market.
What compliant-by-design management software changes
Choosing management software that natively integrates data protection principles, encryption, access control, and automatic deletion after a defined period, considerably simplifies your compliance compared to manual management where each good practice must be applied individually and rigorously by every team member.
This approach, where compliance is built into the tool itself by design, reduces the mental load on your team and the risk of human error, while offering complete traceability useful in the event of an inspection or a question from a customer or competent authority.
The special case of external partners with access to your data
If you share customer data with an external partner, your insurer or a booking platform for example, make sure this sharing remains strictly necessary for contract execution and that this partner itself applies reasonable security standards to protect the information transmitted.
Clearly document in your internal policy which partners receive which data and why, a transparency that greatly facilitates any response to a customer or authority question about the actual flow of their personal information beyond your agency alone.
Raising awareness across the whole organization, not just the counter
Data protection is not only a concern for agents in direct contact with customers: your accountant, your marketing manager, or any external service provider with access to personal information must also understand and respect the same basic principles of security and confidentiality.
Organize minimal awareness training for every new person joining your organization, even outside the operational counter, so this data protection culture permeates your entire structure rather than remaining confined to a single specific team at the agency.
The special case of marketing materials using customer data
If you use testimonials, photos, or customer information in your marketing materials, systematically obtain explicit consent distinct from the simple contractual collection of rental documents, an important legal nuance between what is necessary for contract execution and what falls under separate commercial use.
Document this consent separately and keep a clear record of its acquisition, so you can easily demonstrate that the customer did indeed agree to this specific use of their personal information beyond the strict scope of their initial rental.
Periodically auditing your own internal practices
Organize a simple internal audit once a year, concretely verifying that declared practices match what is actually observed on the ground: access effectively restricted, documents effectively deleted after the defined period, and awareness training effectively given to every new employee joining the agency.
This periodic audit, even a modest one done in-house without an external consultant, often reveals gaps between the written policy and actual practice, a valuable opportunity to correct these gaps before they become problematic in the event of an inspection or a real incident.
Key takeaways
- Clearly inform every customer of how their personal data is used directly within the rental contract.
- Restrict access to customer files to staff genuinely involved in the current rental.
- Limit document retention to a duration justified by your actual accounting and tax obligations.
- Compliant-by-design management software considerably simplifies your overall CNDP compliance.
Frequently asked questions
Is a small agency really subject to CNDP obligations?
Yes, any structure that collects personal data, regardless of its size, is subject to these legal obligations, independent of the volume of customers processed daily by the agency.
How long should a customer's documents be kept after their rental?
It depends on your specific accounting and tax obligations, generally several years, but avoid indefinite retention without clear justification beyond this applicable regulatory duration.
Do you need specialized software to be CNDP compliant?
It is not strictly mandatory, but software that natively integrates these security principles considerably simplifies compliance compared to manual management more exposed to human error.
Should you check the security of external partners who receive our customer data?
Yes, make sure any partner receiving data, insurer or booking platform, itself applies reasonable security standards to protect this information shared within the scope of the contract.
Can you use a customer photo or testimonial in our marketing materials without separate consent?
No, systematically obtain explicit consent distinct from the simple contractual collection, an important nuance between what is necessary for the rental and what falls under separate commercial use.
See also
Related articles
Keep reading
These articles are centered on the topics that matter most to growing Moroccan rental agencies: software, contracts, verification, and fleet control.
Back to blog

