MauritiusIn ForceCybercrime

The Cybersecurity and Cybercrime Act 2021 (Act No. 16 of 2021)

mu-cyber-2021 · Act

Verified entryReviewed by Ademola Adekunbi · 27 June 2026
Summary

The Cybersecurity and Cybercrime Act 2021 (Act No. 16 of 2021) is Mauritius's consolidated cybersecurity and cybercrime statute. Passed by the National Assembly on 24 November 2021 and brought into operation by proclamation on 10 December 2021, it repealed and replaced the Computer Misuse and Cybercrime Act 2003. The Act has two principal limbs. On the institutional and cybersecurity side it establishes a National Cybersecurity Committee to advise Government and implement national cybersecurity and cybercrime policy, places the Computer Emergency Response Team of Mauritius (CERT-MU) on a statutory footing as the national coordinating agency for incident response, and provides for the protection of critical information infrastructure. On the criminal side (Part III) it creates a modern catalogue of offences: unauthorised access to computer data; unauthorised access with intent to commit a further offence; unauthorised access to or interception of a computer service; unauthorised modification of data; the use, possession or supply of devices, programs or access codes for committing offences; denial-of-service and damaging conduct; cyber extortion; cyberterrorism; unlawful disclosure and revenge pornography; and child pornography. The Act adopts a Budapest Convention-style architecture, consistent with Mauritius's accession to that Convention. Procedural powers are exercised through the courts: investigatory authorities may apply for production orders requiring disclosure of stored data, warrants to enter premises and to access, search and seize stored computer data, orders compelling the expedited preservation of data, orders for the real-time collection or recording of traffic data, and orders for the deletion or destruction of computer data. The Act also contains provisions on the admissibility of electronic evidence and on international cooperation and mutual legal assistance in cybercrime matters. Day-to-day enforcement is carried out by the Police (including the Cybercrime Unit) under the supervision of the courts, with CERT-MU coordinating technical response. The legislation attracted civil-society concern over the breadth of certain content-related offences and their potential impact on freedom of expression.

Key provisions
  1. Repealed and replaced the Computer Misuse and Cybercrime Act 2003
  2. Core offences (Part III): unauthorised access, access with intent, unauthorised interception, unauthorised modification, misuse of devices, denial of service and cyber extortion
  3. Aggravated and content offences: cyberterrorism, unlawful disclosure, revenge pornography and child pornography
  4. Establishes the National Cybersecurity Committee and puts CERT-MU on a statutory footing as national incident-response coordinator; provides for protection of critical information infrastructure
  5. Procedural powers via court order: production orders, search-and-seizure warrants, expedited data preservation, real-time traffic-data collection and data-deletion orders
  6. Provisions on electronic evidence and international cooperation/mutual legal assistance (Budapest Convention-aligned)
  7. Enforced by the Police Cybercrime Unit under court supervision, with CERT-MU coordination
Related instruments
Entry history
Entry history
  1. 26 June 2026
    ATLPF Research Team (AI-assisted)
    Initial draft created from the Cybersecurity and Cybercrime Act 2021 (Act No. 16 of 2021) official text (ICTA Mauritius; National Computer Board) and parliamentary explanatory materials. Repeal of the Computer Misuse and Cybercrime Act 2003 confirmed.