Mauritius

Comprehensive

Data Protection Act 2017

Authority: Data Protection Office | Enforcement: Active | Enacted: January 2018

Overview

Mauritius has had data protection legislation since 2004, updated in 2017 to align with GDPR. The Data Protection Office actively enforces compliance. Mauritius is one of the few African countries with comprehensive, actively enforced data protection.

14-Topic Coverage

Data Protection Authority

Fully Addressed

Data Protection Commissioner oversees compliance, handles complaints, and issues enforcement notices.

Data Subject Rights

Fully Addressed

Rights to access, rectification, erasure, restriction, portability, and objection.

Cross-Border Transfer

Fully Addressed

Transfers to countries with adequate protection or with appropriate safeguards.

Breach Notification

Fully Addressed

Must notify Data Protection Commissioner and affected data subjects of personal data breaches.

DPO Requirements

Fully Addressed

DPO required for public bodies and certain private sector organisations.

Children's Data

Fully Addressed

Parental consent required for children under 16.

Penalties & Enforcement

Fully Addressed

Fines up to MUR 200,000 and/or imprisonment up to 5 years.

Sector-Specific Rules

Fully Addressed

BOM financial data rules, ICT Act provisions, health data regulations.

AI & Automated Decisions

Partially Addressed

Right to not be subject to solely automated decisions with legal effects.

Data Localisation

Not Addressed

No general data localisation requirement.

Significant Data Fiduciary

Not Addressed

No equivalent concept.

Government Data

Fully Addressed

Act applies to both public and private sector.