Skip to content

Legal document

Data Protection and Cookies Policy

The executives, managers and professionals who join UNM entrust us with sensitive information: their backgrounds, ambitions, work, sometimes data relating to their organisations. This policy explains how UNM protects this information, in strict compliance with Moroccan Law No. 09-08 and CNDP decisions.

Last updated · May 17, 2026

01

Legal framework

This Policy is established in accordance with:

  • Moroccan Law No. 09-08 of 18 February 2009 on the protection of individuals with regard to the processing of personal data and its implementing decree No. 2-09-165.
  • The decisions and deliberations of the National Commission for the Control of Personal Data Protection (CNDP).
  • Law No. 53-05 of 30 November 2007 on the electronic exchange of legal data.
  • Applicable international conventions, including Council of Europe Convention 108+ to which Morocco has acceded.

For Data Subjects residing in the European Union, the standards of the General Data Protection Regulation (GDPR) apply complementarily where relevant.

02

Data controller

The data controller is Université Numérique du Maroc (UNM), identified in the Legal Notice.

Data Protection Officer (DPO)
dpo@unm.ma · postal address at registered office
CNDP declaration
Receipt number to be confirmed once the declaration is finalised.

03

Enhanced confidentiality commitment

UNM welcomes executives, senior managers, senior public officials and entrepreneurs whose profiles, work and projects may be sensitive in nature.

  • Profile confidentiality: no disclosure of personal information about a Participant's enrolment, admission or journey to unauthorised third parties.
  • Work confidentiality: enhanced confidentiality available for dissertations, projects and case studies containing strategic corporate data.
  • Institutional discretion: no publication, citation or public use of a Participant's name without their express written consent.
  • Geopolitical sensitivity: special consideration for Participants in exposed positions (public responsibilities, leaders of strategic companies, sensitive professions).

04

Data collected

UNM only collects data that is strictly necessary for the purposes pursued.

During browsing (no account): technical data (IP address, browser, OS, pages visited) and cookies.

During account creation: identification (last name, first name, title), contact details (email, phone, country), authentication data (encrypted password).

During application: full identity, contact details, degrees, CV, professional experience, cover letter, financing data.

During the programme: academic data (attendance, assessments, grades, work, dissertation), LMS platform usage data, exchanges with faculty.

05

Legal bases and purposes

Each data processing operation is based on a specific legal basis.

PurposeLegal basisData
User account managementContract performanceIdentification, authentication
Application reviewPre-contractual measuresIdentity, academic, professional
Enrolment and academic follow-upTraining contract performanceAcademic, schooling, work
Diploma issuanceLegal and academic obligationAcademic, identity
Invoicing and accountingLegal obligationFinancial, identification
Institutional communicationConsent (opt-in)Electronic contact details
Anonymised statisticsLegitimate interestAggregated data
Security and fraud preventionLegitimate interestTechnical, access logs

06

Data recipients

Data is accessible only to persons who need to know, strictly within the scope of their duties:

  • UNM internal staff (admissions, schooling, faculty, IT services, finance, academic management).
  • European Business School (EBS): within the academic partnership, certain academic data may be shared for co-delivery of programmes or recognition of prior learning.
  • Technical subcontractors (host, payment provider, LMS supplier, videoconferencing tools, emailing services), contractually bound by equivalent confidentiality obligations.
  • Administrative or judicial authorities upon legal requisition and within applicable obligations.

07

International data transfers

Given UNM's pan-African and international dimension, some processing may involve data transfers outside Morocco.

Transfers to the European Union (notably to the EBS sites in Paris, Barcelona and Berlin) benefit from the protective framework of the European GDPR, recognised by the CNDP as ensuring an adequate level of protection.

Any international transfer is, where applicable, subject to a prior authorisation request from the CNDP, in accordance with articles 43 and following of Law 09-08.

08

Retention periods

Data is kept for the duration strictly necessary to achieve the purposes, plus legal limitation periods.

Data categoryRetention period
Browsing data (no account)13 months maximum
Inactive account3 years after last login
Unsuccessful applications2 years from the decision
Successful applications and participantsProgramme duration + 10 years after graduation
Graduation academic recordsPermanent archives (academic register)
Accounting and tax data10 years (legal obligation)
Marketing prospecting data3 years from last contact
Analytics cookies13 months maximum
Access and security logs12 months

At the end of these periods, data is either deleted or irreversibly anonymised for statistical purposes.

09

Data security

UNM implements technical and organisational measures to ensure the security, confidentiality and integrity of data:

  • Technical measures: encryption of communications (HTTPS/TLS), password hashing, regular backups, environment segregation, firewalls, access monitoring.
  • Organisational measures: access entitlement policy, staff training on confidentiality, contractual commitments of subcontractors, regular audits.
  • Incident response plan: detection, notification (including to the CNDP in case of a breach likely to create a risk to individuals) and remediation procedures.

In the event of a security incident concerning personal data, UNM undertakes to inform the data subjects as soon as possible when the incident is likely to entail a high risk to their rights.

10

Data subject rights

In accordance with Law 09-08, every Data Subject has the following rights:

  • Right of access — Obtain confirmation that data is being processed and obtain a copy.
  • Right to rectification — Have inaccurate or incomplete data corrected.
  • Right to object — Object, for legitimate reasons, to the processing of one's data (including any marketing prospecting).
  • Right to erasure — Obtain the deletion of one's data in cases provided by law.
  • Right to restriction of processing — Request suspension of processing in certain situations.
  • Right to data portability — Receive one's data in a structured, machine-readable format.

These rights may be exercised by contacting the Data Protection Officer by email (dpo@unm.ma) or by postal mail to the registered office. Proof of identity may be requested. UNM undertakes to respond within one (1) month of receipt of the complete request.

11

Cookies policy

A cookie is a small file placed on the User's device when visiting the Website, allowing information about their browsing to be stored.

UNM uses different categories of cookies, classified according to their purpose:

CategoryStatusPurpose
Strictly necessaryAlways activeNavigation, authentication, security.
Audience measurementConsent requiredAnonymised visit statistics.
FunctionalConsent requiredPreference memory (language, accessibility).
Personalisation and marketingConsent requiredRelevant content, campaign measurement.
Third-party social mediaConsent requiredActivated on interaction (LinkedIn, YouTube).

On the first visit, a consent banner allows the User to accept, decline or fine-tune non-essential cookies. The User can change preferences at any time via the "Manage my cookies" link at the bottom of every page.

Cookies have a maximum lifespan of 13 months. Data collected via cookies is kept for a maximum of 25 months.

12

Policy modification

UNM reserves the right to modify this Policy to adapt it to legal, regulatory, technical or organisational changes. Substantial changes are clearly notified to Users with an account. The applicable version is the one in force at the date of consultation.

13

Contact

For any question concerning this Policy or the processing of your data:

Data Protection Officer
dpo@unm.ma
CNDP
National Commission for the Control of Personal Data Protection — 2nd Tour Ihssane, Hay Riad, Rabat — www.cndp.ma