Data Protection Act 2017
Data Protection Office
Data Protection Office
Mauritius regulates personal data through the Data Protection Act 2017. The Act replaced the earlier data protection regime and was brought into force on 15 January 2018. Its stated purpose is to strengthen the control and personal autonomy of data subjects over their personal data in line with current international standards.
The Mauritian framework is structurally close to modern European-style privacy law. It uses the language of controllers, processors, data subjects, special categories of personal data, data protection impact assessments, breach notification, and cross-border transfer safeguards. That makes it familiar to organisations already working with GDPR-type frameworks, but it should not be treated as a copy-and-paste exercise. Mauritius has its own registration system, Data Protection Office, Commissioner powers, and transfer requirements.
The Data Protection Act 2017 is the core statute. It applies to automated processing of personal data and to non-automated processing where the data forms, or is intended to form, part of a filing system. The Act binds the State, treats Ministries and Government departments separately for its purposes, and applies to controllers or processors established in Mauritius. It also reaches controllers and processors not established in Mauritius where they use equipment in Mauritius for processing, other than merely for transit.
The Data Protection Office is the supervisory authority. The Office is headed by the Data Protection Commissioner and acts with complete independence and impartiality. The Commissioner is responsible for ensuring compliance, investigating complaints, issuing enforcement notices, maintaining the register of controllers and processors, conducting audits, issuing codes and guidelines, and exercising the statutory powers given under the Act.
Accountability by design is the operating model. Controllers must adopt policies and implement appropriate technical and organisational measures to ensure and demonstrate compliance. These measures include security controls, records of processing, data protection impact assessments, prior authorisation or consultation where required, and designation of an officer responsible for data protection compliance issues.
A Mauritian compliance programme begins with identifying whether the organisation is acting as a controller, processor, or both. The controller determines the purposes and means of processing and has decision-making power over processing. The processor processes personal data on behalf of a controller. The distinction matters because controllers carry the core accountability burden, while processors have independent statutory duties in areas such as security, breach escalation and unlawful disclosure.
Every controller and processor must ensure that personal data is processed lawfully, fairly and transparently; collected for explicit, specified and legitimate purposes; limited to what is necessary; accurate and kept up to date; retained only as long as necessary; and processed in accordance with the rights of data subjects. These are not merely policy principles. They shape collection forms, privacy notices, retention rules, vendor arrangements, cross-border transfers, security controls and complaint workflows.
The Act also creates a practical rights framework. Data subjects have rights of access, rights relating to automated individual decision making, rights to rectification, erasure and restriction, and the right to object. Direct marketing is specifically addressed: where personal data is processed for direct marketing, the data subject may object, and the data must no longer be processed for that purpose.
Start with registration and role mapping. Identify all processing operations, decide whether the organisation is a controller or processor for each activity, and confirm whether registration requirements have been satisfied. Then create a record of processing operations and align privacy notices with the collection requirements under the Act.
Next, test the high-risk processing layer. If a processing operation is likely to result in a high risk to the rights and freedoms of data subjects, a data protection impact assessment may be required. In certain cases, prior authorisation or consultation with the Data Protection Office may be necessary before the processing begins.
Finally, strengthen incident response and transfer governance. Personal data breaches must be escalated quickly, with notification to the Commissioner where required and communication to data subjects where the breach is likely to result in a high risk. Transfers outside Mauritius must be supported by appropriate safeguards, explicit consent after risk disclosure, or another statutory transfer ground.
Data Protection Act 2017 - the primary Mauritian data protection statute governing controllers and processors, registration, processing principles, controller duties, breach notification, special categories of personal data, child data, DPIAs, prior consultation, cross-border transfers, data subject rights, offences and enforcement.
Mauritius compliance is an accountability exercise. You need to know what data you process, why you process it, whether you are a controller or processor, whether registration is required, whether special-category or child data is involved, whether processing is high risk, whether transfers outside Mauritius are protected, and whether your organisation can respond to access, erasure, objection and breach events without improvising. The law analysis explains how those obligations translate into operating controls.