"You say the hosting is secure and compliant. Specifically, who is responsible for what when something goes wrong, and what are you actually able to sign?"
This question surfaces in every serious negotiation once a project involves sensitive or regulated data. Yet most vendor answers stay vague: displayed certifications, uptime promises, technical metrics.
What actually matters during an incident (outage, breach, compromise, unavailability) is the contractual split of liability. Who legally answers for what. What a development agency can actually guarantee versus what it merely resells from a hosting provider whose terms it does not control. The difference between a certified host and a self-administered server, which only reveals itself when everything stops.
This article does not pick a hosting option (public cloud, sovereign cloud, dedicated server). It addresses contractual liability splits and the five questions that expose a vendor unable to guarantee what it sells. For strategic advice on infrastructure choices, visit our digital consulting services or explore our system integration solutions.
Data Controller and Processor: Who Answers for What
Morocco's Law 09-08 on personal data protection, like the European GDPR, draws two clear legal roles: the data controller (the company that decides what is done with the data) and the processor (the entity that processes data on the controller's instructions).
Any agency that develops then hosts your business application acts as a processor under the law. It therefore carries specific obligations, including mandatory breach notification (Article 24 of Law 09-08), documentation of security measures, and the ability to demonstrate compliance.
Except many vendors themselves subcontract hosting to AWS, OVHcloud, or a local provider. In that case, the host becomes a sub-processor. Contractual liability toward the end client remains with the agency, because it signed the contract, but if the host has no enforceable SLA (Service Level Agreement), the agency technically cannot commit to what it does not control.
Concretely, this means if the host loses your data or suffers a breach, the agency answers civilly to you, but can only turn against the host if it has its own contract granting that right.
That is why the first question to ask is simple: who, legally, stands liable in case of breach or unavailability? If the answer is "our hosting partner," ask to see the contract linking the agency to that host, and verify it contains the same guarantees you are being promised.
What a Development Agency Can Contractually Guarantee, and What It Merely Resells
A custom development agency controls code, application architecture, data flows. It can commit contractually to the security of the code it writes, penetration testing, adherence to best practices (OWASP, SQL injection prevention, session management, encryption of sensitive data in the database).
However, for everything that belongs to the underlying infrastructure (physical datacenter availability, network redundancy, network-level DDoS protection, hardware resilience), the agency depends on its host's guarantees. If it has not subscribed to an enforceable SLA with 99.9% availability guarantee, it cannot legally commit you to that level.
The boundary is simple: the agency can guarantee what it codes and administers; it can only relay the guarantees of what it subcontracts.
In a well-drafted contract, this line is drawn explicitly. For example:
- The agency contractually guarantees application security, code compliance, and management of application backups.
- The agency commits to selecting a certified host (ISO 27001, HDS if healthcare, etc.) and provides the client with the host's certificates.
- The agency transfers to the client the hosting general terms, including availability SLA and liability clauses in case of data loss.
If your contract contains none of these clauses, the agency guarantees nothing contractually; it merely promises verbally. On the day of the incident, you are left with no enforceable recourse.
Certified Host or Self-Administered Server: The Difference Shows on Incident Day
There is a fundamental difference between a certified host operating a standards-compliant datacenter (ISO 27001, Tier III, HDS for healthcare) and an agency that rents a VPS from a generic provider and self-administers it.
In the first case, the host contractually assumes hardware availability, physical infrastructure backup, power redundancy, physical site security, and often, managed services (automated backups, snapshots, restoration testing).
In the second case, everything rests on the agency's operational competence. If it has set up automated backups, regularly tested restoration, configured active monitoring, and documented recovery procedures, risk is controlled. If it has not (and many do not, because it represents non-billable time), you discover the problem when you need it.
The difference shows at the moment of incident. With a certified host, you have a contractual counterparty, an enforceable SLA, and documented procedures. With a self-administered server without documentation or recovery tests, you depend on the operational availability of the single administrator who knows the infrastructure.
That is why the proof to demand is simple: ask for the last successful restoration test report. If the agency cannot provide it, that means it has never tested restoration, so it cannot guarantee it works.
Data Leaving Territory: The Question to Settle Before Technical Choice
If your company processes personal data (customers, suppliers, employees), you must address the geographic location of hosting. Law 09-08 does not formally prohibit it, but it requires notification to CNDP (National Commission for Personal Data Protection) if data is transferred outside Morocco to a country whose legislation does not offer equivalent protection.
In practice, this means if you host on AWS eu-west-1 (Ireland), you are in a country recognized as offering equivalent protection (GDPR), so no notification needed. If you host on AWS us-east-1 (Virginia), you must notify CNDP and document contractual safeguards (standard contractual clauses, Privacy Shield if applicable, or equivalent mechanisms).
The frequent trap is discovering after signature that the host chosen by the agency is outside territory without documented guarantees. In that case, you find yourself in potential non-compliance without having chosen it.
Best practice is to settle contractually before any technical choice. For example:
- Hosting exclusively within EU or Morocco (contractual clause).
- In case of leaving territory, CNDP notification at agency's expense, and transmission to client of enforceable contractual safeguards.
If your agency proposes "international" hosting without specifying where or documenting guarantees, it is a warning signal.
Backup, Tested Restoration, Reversibility: The Three Proofs to Demand
Beyond commercial promises, three concrete proofs allow verifying that hosting is truly controlled:
1. Documented Automated Backup
Not "yes, we do backups," but a document describing frequency (daily, weekly, monthly), retention (how many versions kept), location (same datacenter or geographically distant), and scope (database only, or also application files, server configurations).
2. Tested Restoration Report
A backup that has never been tested is a theoretical backup. Demand the last successful restoration test report, dated within three months. If the agency cannot provide it, that means it does not test its backups, so it cannot guarantee they work.
3. Documented Reversibility Procedure
In case of contract termination or vendor change, you must be able to recover your data in an exploitable format. Demand a documented reversibility procedure: complete database extraction (SQL format or equivalent), recovery of application files, export of configurations necessary for third-party takeover.
If your contract does not explicitly mention these three points, you depend on the agency's operational goodwill, not an enforceable contractual commitment.
Clauses to Include in the Hosting Contract
A well-drafted hosting contract does not merely promise "secure hosting." It contractually specifies enforceable obligations. Here are essential clauses to demand:
Article on liability split: clear distinction between what the agency directly guarantees (application security, backups, system administration) and what it subcontracts to a third-party host (hardware availability, network redundancy). If the agency subcontracts, the client must receive a copy of the contract linking the agency to the host.
Article on geographic location: clause specifying where data is hosted (country, region), and in case of leaving Moroccan territory, agency commitment to notify CNDP and document contractual safeguards (standard contractual clauses, equivalent certifications).
Article on backups: frequency, retention, location, and agency obligation to provide the client, on request, the last successful restoration test report. Contractual commitment on maximum restoration delay (RPO, Recovery Point Objective: how much data can be lost, for example "last daily backup" means up to 24 hours loss).
Article on reversibility: agency obligation to hand over to the client, at contract end or on request, all data in an exploitable format, including database, files, configurations, within a contractual timeframe (for example 30 calendar days).
Article on incident notification: agency obligation to notify client within a contractual timeframe (for example 24 hours) in case of data breach, prolonged unavailability, or any incident liable to affect service security or availability.
Article on availability SLA: if the agency commits to an availability rate (for example 99.5% monthly), the contract must specify how this rate is measured, what counts as unavailability (planned maintenance excluded or included), and contractual penalties for non-compliance (for example service credit proportional to unavailability time).
If your current contract contains none of these clauses, you have a major contractual risk. On the day of incident, you discover nothing is enforceable.
Five Questions That Expose a Vendor Reselling a VPS
Here are five simple questions to ask during negotiation. The answers will immediately tell you whether you face controlled hosting or merely a resold VPS.
1. Where is data hosted, and can you show me the datacenter compliance certificate? If the answer is "at our partner" without being able to provide the host's name or any certificate (ISO 27001, Tier III, HDS), it is a generic VPS without guarantee.
2. Can you show me the last successful restoration test report? If the answer is "we do automated backups" without being able to provide a dated successful test report, that means they never test their backups, so they cannot guarantee they work.
3. What is the contractual restoration timeframe in case of total server loss? If the answer is "it depends" or "we'll do our best," that means there is no contractual RTO (Recovery Time Objective), so no enforceable commitment on recovery delay.
4. If I change vendors, in what format and timeframe can I recover my data? If the answer is vague ("we'll give you a dump"), ask for a documented reversibility procedure. If it does not exist, you take a technical dependency risk.
5. If the host loses my data, who is legally liable to me, and on what contractual basis? If the answer is "our hosting partner is liable," ask to see the contract linking the agency to that host. If the agency refuses to show it or does not have one, that means it cannot turn against the host, so it cannot guarantee you recourse.
A serious vendor answers these five questions in under ten minutes, documents in hand. If it hedges or promises to "check later," it does not control what it sells.
What You Must Keep In-House No Matter What
Even with perfectly controlled hosting, certain critical information must remain under your direct control, never entirely delegated to the vendor.
Last-resort administrator access: you must retain direct root or administrator access to the server, or at minimum a separate account with equivalent rights. If only the vendor holds administrator access, you depend on its operational availability in case of emergency.
Master encryption keys: if your sensitive data is encrypted in the database (bank cards, health data, confidential information), the master encryption key must never be stored only at the vendor. You must keep a copy in a secure offline vault, or use an HSM (Hardware Security Module) whose access you control.
SSL certificates and domain names: your domain's SSL certificate must be issued in your company's name, not the agency's. Likewise, the domain name must be registered under your corporate name. If the agency holds the domain, it can technically deprive you of it in case of dispute.
Offline backups: in addition to the agency's automated backups, keep at least one monthly offline backup (encrypted external hard drive, separate cloud storage under your control). This guarantees that in case of total infrastructure compromise, you have an independent recovery point.
Technical documentation: network architecture, database schemas, critical configurations, recovery procedures. This documentation must contractually belong to you and be regularly updated. If it exists only in the vendor administrator's head, you are in total operational dependency.
FAQ
What is the difference between a data controller and a processor under Law 09-08?
The data controller is the company that decides what is done with personal data (purpose, retention period, who accesses it). The processor is the one who processes data on the controller's instructions, without decision autonomy. An agency that develops and hosts your application is legally a processor under the law, therefore bound by specific obligations of security, breach notification, and documentation of technical measures.
If my host is in Europe, must I notify CNDP?
It depends on the country. If hosting is in an EU country (therefore subject to GDPR, recognized as offering equivalent protection), no specific notification is required, because protection is considered equivalent. However, if hosting is outside EU (for example United States, China, Russia), you must notify CNDP and document enforceable contractual safeguards (standard contractual clauses, equivalent certifications, recognized transfer mechanisms).
How to verify a backup actually works?
The only reliable way is to regularly test restoration. Ask your vendor to schedule a restoration test on a test environment (never in production), and provide you a detailed report attesting that database, application files, and configurations were successfully restored and that the application works after restoration. A successful test dated within three months is concrete proof. If your vendor refuses or systematically postpones, it never tests its backups.
What to do if my agency refuses to show me the contract with the host?
It is a major warning signal. If the agency promises you guarantees (availability, security, compliance) but refuses to show you the contract linking the agency to the host, that means either it has no enforceable contract (therefore no way to turn against the host in case of problem), or the contract does not contain the promised guarantees. In that case, contractually demand that the agency directly assume liability for these guarantees, and if it refuses, consider changing vendors.
How long should business application backups be retained?
It depends on your regulatory obligations and risk tolerance. Generally, daily retention over 30 days, weekly over 12 weeks, and monthly over 12 months is a good compromise for a business application. If you process data subject to archiving obligations (accounting, healthcare, financial services), you must keep archived backups for the legal duration (10 years for accounting in Morocco, for example). Verify that your hosting contract explicitly provides this retention, otherwise the agency can delete old backups without warning you.
