Back to news
Human Capital

Data Protection: When Compliance Becomes a Financial, Operational and Human Capital Issue

Data Protection: When Compliance Becomes a Financial, Operational and Human Capital Issue

Personal data protection can no longer be treated solely as a legal or administrative matter.

Customers, employees, applicants, suppliers, partners, banking information, access credentials and other personal information are now embedded in everyday business operations.

In Morocco, personal data processing is governed by Law 09-08 and overseen by the CNDP — the National Commission for the Control of Personal Data Protection.

The CNDP officially has investigation and control powers to verify compliance with the law, while organizations processing personal data are subject to security, notification and other obligations depending on the nature of their activities. CNDP

In an interview published by Médias24, Mohamed Romdane, Managing Director of Formafast Consulting, describes an environment in which companies increasingly need to demonstrate that their protection mechanisms actually work in practice. Médias24

This raises a broader business question:

should data protection still be viewed primarily as a compliance cost, or has it become a financial and governance issue?

Compliance has a direct financial dimension

Compliance requires investment.

Data mapping, audits, legal support, access management, security systems, employee training and internal processes all require resources.

But focusing only on those costs gives an incomplete picture.

Organizations also need to consider the potential economic impact of weak data governance:

business disruption, remediation expenses, management time, customer loss, reputational damage, litigation and regulatory consequences.

The financial question therefore shifts from:

“How much does compliance cost?”

to:

“What is the economic cost of the risk we choose not to control?”

This brings data protection directly into the agenda of CFOs, executive teams and boards.

Trust can become a commercial asset

Data protection is not only about avoiding downside risk.

It can also influence an organization’s ability to win and retain business.

This is particularly relevant for Moroccan companies serving international customers.

Law 09-08 governs personal-data processing and international transfers, while foreign clients may impose additional contractual and technical requirements.

The CNDP confirms that data processing carried out in Morocco on behalf of foreign principals remains subject to Moroccan data-protection requirements. CNDP

In the Médias24 interview, this economic dimension is specifically highlighted for nearshoring, call centers and software development.

In these industries, the ability to demonstrate reliable data protection can become part of the commercial proposition itself. Médias24

Compliance can therefore evolve from a constraint into a business trust factor.

Technology alone does not create compliance

Purchasing security tools does not automatically create effective data governance.

An organization may have firewalls, antivirus software, identity management and data-loss prevention systems while remaining exposed if responsibilities and everyday behaviors are poorly managed.

Moroccan law requires appropriate technical and organizational measures based on the risks involved and the nature of the personal data being processed. CNDP

This creates another financial question:

where should investment be prioritized?

Organizations need to direct budgets toward the risks with the greatest operational and economic impact.

Data protection increasingly becomes a form of enterprise risk management.

HR data is directly exposed

Human Resources is one of the functions that handles the largest volumes of personal information.

CVs, employment contracts, compensation information, bank details, assessments, attendance records and other employee information may all be sensitive.

The CNDP itself identifies payroll, access control, video surveillance and employee-related information among common forms of personal-data processing. CNDP

This makes data protection a Human Capital issue as well.

Organizations need to determine who can access which information, how access rights change when employees move between roles, what happens when someone leaves, and whether managers understand the boundaries around information sharing.

Compliance therefore cannot exist only on paper.

It needs to become part of everyday behavior.

AI changes the financial equation again

Artificial intelligence makes this challenge even more important.

Companies want AI tools because they can improve productivity, accelerate analysis and automate repetitive tasks.

But employees can also transfer confidential information to external services in seconds.

The Médias24 interview specifically identifies AI services as a new potential channel for data leakage and argues for controlled usage rather than blanket prohibition. Médias24

Executives therefore face a new trade-off:

how can organizations capture AI productivity gains without creating additional financial and regulatory exposure?

The answer requires governance, classification, employee education and appropriate controls.

Finance, HR, IT and Legal need to work together

Effective data governance cannot belong to only one department.

Finance needs visibility over financial exposure.

IT and cybersecurity need to secure systems.

Legal teams need to manage obligations and contracts.

HR needs to protect employee information and embed controls throughout the employee lifecycle.

Executive management needs to determine priorities and risk appetite.

Data protection therefore becomes a genuine cross-functional governance issue.

From administrative compliance to demonstrable compliance

Another important shift concerns evidence.

It is no longer enough to have policies.

Organizations need to demonstrate that those policies operate effectively.

The CNDP states that data controllers must protect personal-data integrity and confidentiality, manage third parties appropriately and complete the required regulatory procedures. CNDP

The Médias24 interview similarly emphasizes auditable evidence such as access records, activity logs, data flows, audits and incident-response records. Médias24

Compliance therefore becomes a continuous operating process.

Data protection is ultimately about protecting value

Data protection has traditionally been treated as a legal or IT issue.

That view is becoming too narrow.

Weak data governance can affect operations, contracts, clients, reputation and ultimately enterprise value.

Strong governance, on the other hand, can help companies work with demanding partners and adopt new technologies under more controlled conditions.

Compliance has a cost.
Unmanaged risk has a cost as well.

The real leadership challenge is not to buy more tools indiscriminately.

It is to identify which data creates value, which risks could destroy that value, and which financial, technological and human resources are required to protect it.

For MAK Associates, this also reinforces a broader principle: regulatory and technological transformation requires clear governance, appropriate capabilities, accountable leadership and coordination between key business functions.

News source: Médias24 — “Protection des données. La CNDP passe du conseil au contrôle : ce qui change pour les entreprises marocaines,” partner content published October 6, 2026.

Keep reading

Read more

Strategic intelligence

Stay informed on the changes that matter

Receive our monthly selection of exclusive analyses, regulatory breakdowns, and market insights directly in your inbox.

FR