Act 2017
Data Protection Act 2017
Issued by Data Protection Office
Effective: 15 Jan 2018
Last amended: 16 Jan 2026
Plain-English summary
The Data Protection Act of 2017 is an extremely modern privacy law that became effective on 15 January 2018 and helped align the legal framework for handling digital information in Mauritius with internationally accepted standards like the EU's General Data Protection Regulation (GDPR). Managed by the independent Data Protection Office, the legislation mandates all companies, whether local or foreign, operating in Mauritius to register themselves as either a data controller or processor for a period of three years, which is renewable after every three years. The Act provides strong rights to the data subjects such as data portability, data access, and the right to erasure. Furthermore, businesses operating in Mauritius are required to report significant data breach incidents within 72 hours of occurrence as per the legal requirements of the Act. Non-compliance with the Data Protection Act is considered a criminal offence, and strict statutory penalties ranging from fines of up to MUR 200,000 to five years of jail time are prescribed for such non-compliance with the Act.
Who it applies to
Banking · Asset & Wealth Management · Telecom & Tech
Topics
Data Protection & Privacy
Obligations arising from this instrument
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| Lawful basis, notice and data subject rights | Ongoing | DPO | official | |
Personal data protection in Mauritius is guided by the provisions of the Data Protection Act 2017 (DPA 2017) and regulated by the Data Protection Office, and the law is consistent with international practices [fscmauritius.org]. Under this legislation, the data controller has an obligation to ensure that there is a sound legal basis for processing the personal data, which can be consent, necessity for performing the contract or legal obligation. There is an obligation to present individuals with a clear Privacy Notice containing details of the reasons for the processing, the period of time for which the data will be retained, and the transfer of the information to other parties. The rights of the individual under DPA 2017 include the right of access, rectification, erasure, objection, and restriction of automated decision making. Failure to comply with these obligations results in criminal penalties of imprisonment and fines. |
||||
| Personal data breach notification | Deadline Event-based | DPO | official | |
The requirement for breach notification of personal data in Mauritius requires that the data controller notify the DPO of the breach without delay and, if possible, not later than 72 hours from discovering the breach. Under Section 37 of the Data Protection Act 2017, data processors shall notify the breach to their respective controllers immediately, and the controllers should notify the affected person directly if the breach involves a high risk to the rights and freedoms of the individual. The notification of the breach should detail the kind of breach, type of personal data involved, likely consequences, and measures taken to mitigate the breach. Failure to comply with breach notification requirements is considered a criminal offense and punishable by a MUR 200,000 fine and 5 years of imprisonment. |
||||
| No obligations match these filters. | ||||
Latest news
No related news yet. We publish updates as regulators act.