Morocco Law 09-08 Article 12 Sensitive Personal Data Processing Authorisation. Sensitive data categories (donnees sensibles): racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union membership + health + sexual life + criminal convictions + administrative sanctions + offences. Processing requires CNDP prior authorisation + grounds limited to: explicit consent + public interest authorised by law + vital interests + non-profit body for members + processing made public by data subject + legal claims. Biometric Access Control + Authorisation (Article 12 + CNDP Guidelines): biometric processing for access control + identification + verification of identity requires CNDP authorisation + proportionality assessment + alternative non-biometric option + retention limited + technical safeguards + non-genetic biometric template encryption + secure storage + workforce notification + employee + works council consultation. Whistleblower Hotlines (CNDP Guideline 2018): processing of personal data via whistleblower hotlines (anti-corruption + ethics + fraud reports) requires CNDP authorisation + restricted purposes + designated workforce categories + anonymity + chain of custody + sub-1-year retention for unsubstantiated reports + 5-year for substantiated + access controls + investigation team training + Sapin II + FCPA + UK Bribery Act coordination for multinationals.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.