Published on · By the IT LABS PRO team
When you hand your project to a team in another country, three questions come up sooner or later: is my information protected, who owns what is built, and is the personal data of my customers handled lawfully? None of them is complicated if it is settled in writing at the start. This checklist lists the points to cover. It is a practical guide, not legal advice: have your contract reviewed by a lawyer who knows your jurisdiction, especially for sensitive data or large projects.
1. Confidentiality (NDA)
A non-disclosure agreement is usually signed before you share your project details, then reinforced by the confidentiality clause of the main contract.
- What is confidential: your business information, documents, code, data, and the very existence of the project if you want it kept quiet (common for agencies working white-label).
- Who is bound: the company, but also its employees and any subcontractors, who should sign equivalent commitments.
- How long: during the project and for a period afterwards (often several years), and without time limit for trade secrets and personal data.
- Exceptions: information already public, or that the provider already knew, or that a court orders it to disclose.
- Return or destruction of your information at the end of the relationship.
- Portfolio use: whether the provider may mention you or show your project as a reference. For white-label work, it should not.
2. Intellectual property of the code
Software is protected by copyright in Morocco, as in Europe. Without a clear clause, the question of who owns code written by a contractor can become uncertain. Do not leave it to chance.
- Assignment of rights: the contract should state that the economic rights to the code, designs and documents created for you are assigned to you, usually once the corresponding invoices are paid. The assignment should list the rights (reproduction, modification, distribution, commercial use), the territory (worldwide) and the duration.
- Continuous access: the code should live in a repository you can access throughout the project, not be delivered as a zip file at the end.
- Open-source components: the provider should list the libraries used and their licences, and avoid licences incompatible with your use (some impose publishing your own code).
- The provider’s own tools: if the provider reuses its own components, you should get at least a perpetual, free licence to use them in your product.
- Subcontractors: any rights they hold must also be passed on to you.
- Warranty: the provider guarantees that what it delivers does not infringe anyone else’s rights.
3. Personal data: the GDPR side
If your project involves personal data of people in the European Union (your customers, users, employees) and the Moroccan team can access it, that is a transfer of personal data outside the EU under the GDPR.
- No EU adequacy decision for Morocco: as far as we know, the European Commission has not adopted one, so transfers need appropriate safeguards. The usual tool is the European Commission’s Standard Contractual Clauses (SCCs), signed between you and the provider.
- A data processing agreement (article 28 GDPR): the provider processes data only on your instructions, with confidentiality, security measures, assistance, deletion at the end, and audit rights.
- A transfer risk assessment: document why the transfer is acceptable and which measures protect the data.
- Minimise access: very often, developers do not need real personal data at all. Use anonymised or fake data for development and testing; that removes most of the problem.
4. Personal data: the Moroccan side
The provider, established in Morocco, is also subject to Moroccan law no. 09-08 on the protection of personal data, overseen by the CNDP. Morocco has also acceded to the Council of Europe’s Convention 108 on data protection. In practice, a serious Moroccan provider will:
- apply security measures to the data it handles;
- respect the confidentiality obligations of law 09-08;
- complete the formalities with the CNDP where its own processing requires them.
Our article on law 09-08 and the CNDP explains the Moroccan rules in more detail.
5. Security in practice
- Individual accounts for each person, with two-factor authentication where possible; no shared passwords.
- Access limited to the environments and data each person needs, removed when they leave the project.
- No production data on laptops; encrypted disks.
- Code reviews and dependency updates to avoid known vulnerabilities.
- A procedure and a deadline for informing you of any security incident.
6. The rest of the contract
- Governing law and jurisdiction: which country’s law applies and which courts (or arbitration) settle disputes. Choose something both sides can live with.
- Liability: caps and exclusions, which should not cover breaches of confidentiality or data protection too lightly.
- Non-solicitation: whether you may hire the provider’s staff directly, and on what terms.
- Termination and hand-over: notice period, delivery of code, documentation and credentials, transition support.
The checklist
- NDA signed before sharing details, covering employees and subcontractors.
- Confidentiality clause in the main contract, with a duration after the end.
- Assignment of IP rights to you, worldwide, on payment.
- Code in a repository you control or can access at all times.
- List of open-source components and licences.
- Data processing agreement and, for EU personal data, Standard Contractual Clauses.
- Anonymised or fake data for development and tests.
- Security measures and incident notification written down.
- Governing law, jurisdiction and liability agreed.
- Hand-over plan if the relationship ends.
Frequently asked questions
Is an NDA signed with a Moroccan company enforceable?
A contract freely agreed between companies is binding in Morocco as elsewhere. What matters is a clear text, the chosen governing law and jurisdiction, and a provider whose reputation you have checked.
Do I need the Standard Contractual Clauses if the team never sees personal data?
If no personal data from the EU is accessible to the team, there is no transfer to frame. That is why development on anonymised or fake data is so useful.
Who owns the code if the contract says nothing?
It can become unclear, and by default the author often keeps the rights. Always include an explicit assignment clause.
In short
Before work starts, settle confidentiality (NDA covering staff and subcontractors), ownership (assignment of rights and continuous access to the code) and personal data (a data processing agreement, Standard Contractual Clauses for EU data, and as little real data as possible). IT LABS PRO signs NDAs, assigns code ownership to its clients and works white-label for agencies: see our offshore software development page.
Sources
- European Commission, Standard Contractual Clauses for international transfers: commission.europa.eu
- European Commission, adequacy decisions: commission.europa.eu
- Council of Europe, Convention 108: coe.int
- CNDP (Morocco), in French: cndp.ma
