Data Protection Act 2017
mu-dpa-2017 · Act
The Data Protection Act 2017 (DPA 2017) is Mauritius’s primary legislative instrument for the protection of personal data, enacted as Act No. 20 of 2017, published in the Government Gazette on 23 December 2017, and brought into force on 15 January 2018 by Proclamation No. 3 of 2018. It repeals and replaces the Data Protection Act 2004 and significantly modernises the framework by aligning it more closely with the principles of the EU General Data Protection Regulation (GDPR), reflecting Mauritius’s role as a regional financial services hub with substantial cross-border data flows. The Act applies to any person who, alone or jointly with others, controls the collection, holding, processing, or use of personal data in Mauritius, and extends to controllers outside Mauritius who use equipment located in the country for processing purposes. Exemptions apply to processing for personal or household purposes, journalism, literary or artistic expression, and certain national security activities. All data controllers must register with the Data Protection Commissioner before processing personal data. Registration is renewable and failure to register constitutes a criminal offence attracting a fine of up to MUR 200,000 and imprisonment of up to five years. The Act enshrines eight data protection principles covering lawfulness and fairness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Data subjects enjoy a comprehensive suite of rights: the right to be informed, the right of access, the right to rectification, the right to erasure, the right to object to processing for direct marketing, and the right not to be subject to automated decision-making that produces significant effects. Rights may be enforced by lodging complaints with the Data Protection Commissioner. Controllers must notify the Data Protection Commissioner of any personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach poses a high risk to data subjects’ rights and freedoms, affected individuals must also be notified directly and promptly. Cross-border data transfers are permitted only where the destination country ensures an adequate level of protection, as assessed and periodically published by the Commissioner. Transfers to non-adequate countries require specific safeguards, such as standard contractual clauses or binding corporate rules, or rely on statutory derogations including data subject consent. Penalties include fines of up to MUR 200,000 and imprisonment for up to five years. The Commissioner may also issue enforcement notices and stop-processing orders. The Data Protection Office, an independent public authority not subject to the direction of any other person or authority, oversees registration, enforcement, and public education on data protection matters.
- All data controllers must register with the Data Protection Commissioner before processing personal data; failure to register attracts fines of up to MUR 200,000 and imprisonment for up to five years
- Data subjects have rights to access, rectification, erasure, objection to direct marketing, and protection from automated decision-making with significant legal or similar effects
- Controllers must notify the Data Protection Commissioner of personal data breaches within 72 hours of becoming aware, and must notify affected data subjects where the breach poses a high risk
- Cross-border transfers are permitted only where the destination country provides adequate protection as assessed by the Commissioner, or where specific safeguards such as standard contractual clauses are in place
- Processing of sensitive personal data (health, racial origin, biometric, criminal record) requires explicit consent or a statutory derogation
- The Commissioner may issue enforcement notices and stop-processing orders and conduct audits and investigations
- Criminal penalties include fines of up to MUR 200,000 and imprisonment for up to five years for offences including unlawful processing and obstruction of the Commissioner