Mauritius
ComprehensiveData Protection Act 2017
Authority: Data Protection Office | Enforcement: Active | Enacted: January 2018
Overview
Mauritius has had data protection legislation since 2004, updated in 2017 to align with GDPR. The Data Protection Office actively enforces compliance. Mauritius is one of the few African countries with comprehensive, actively enforced data protection.
14-Topic Coverage
Data Protection Authority
Fully AddressedData Protection Commissioner oversees compliance, handles complaints, and issues enforcement notices.
Consent Requirements
Fully AddressedConsent required as primary basis. Must be freely given, specific, and informed.
Data Subject Rights
Fully AddressedRights to access, rectification, erasure, restriction, portability, and objection.
Cross-Border Transfer
Fully AddressedTransfers to countries with adequate protection or with appropriate safeguards.
Breach Notification
Fully AddressedMust notify Data Protection Commissioner and affected data subjects of personal data breaches.
DPO Requirements
Fully AddressedDPO required for public bodies and certain private sector organisations.
Children's Data
Fully AddressedParental consent required for children under 16.
Penalties & Enforcement
Fully AddressedFines up to MUR 200,000 and/or imprisonment up to 5 years.
Sector-Specific Rules
Fully AddressedBOM financial data rules, ICT Act provisions, health data regulations.
Cookie/Tracking
Partially AddressedGeneral consent requirements apply. ICT Act addresses electronic communications.
AI & Automated Decisions
Partially AddressedRight to not be subject to solely automated decisions with legal effects.
Data Localisation
Not AddressedNo general data localisation requirement.
Significant Data Fiduciary
Not AddressedNo equivalent concept.
Government Data
Fully AddressedAct applies to both public and private sector.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Mauritius's regulations.
Book a Consultation