Mauritius

MU · MUS · Middle East & Africa · Last verified 29 Sep 2026

4 regulators · 4 instruments · 6 obligations · 1 upcoming deadline

Mauritius — hero image

Act 2017

Data Protection Act 2017

Issued by Data Protection Office

Effective: 15 Jan 2018

Last amended: 16 Jan 2026

Plain-English summary

The Data Protection Act of 2017 is an extremely modern privacy law that became effective on 15 January 2018 and helped align the legal framework for handling digital information in Mauritius with internationally accepted standards like the EU's General Data Protection Regulation (GDPR). Managed by the independent Data Protection Office, the legislation mandates all companies, whether local or foreign, operating in Mauritius to register themselves as either a data controller or processor for a period of three years, which is renewable after every three years. The Act provides strong rights to the data subjects such as data portability, data access, and the right to erasure. Furthermore, businesses operating in Mauritius are required to report significant data breach incidents within 72 hours of occurrence as per the legal requirements of the Act. Non-compliance with the Data Protection Act is considered a criminal offence, and strict statutory penalties ranging from fines of up to MUR 200,000 to five years of jail time are prescribed for such non-compliance with the Act.

Who it applies to

Banking · Asset & Wealth Management · Telecom & Tech

Topics

Data Protection & Privacy

Obligations arising from this instrument

Obligation Timing Regulator Source Detail
Lawful basis, notice and data subject rights Ongoing DPO official
Personal data breach notification Deadline Event-based DPO official

Official source

Latest news

No related news yet. We publish updates as regulators act.

Browse all newsSubscribe for updates