Mauritius
East Africa
Mauritius has one of the more modern data protection regimes on the continent. Its primary instrument, the Data Protection Act 2017 (Act No. 20 of 2017), was published on 23 December 2017 and entered into force on 15 January 2018, repealing and replacing the Data Protection Act 2004. The 2017 Act was deliberately aligned with the EU GDPR, reflecting the country's role as a regional financial-services hub with substantial cross-border data flows. It applies to any person who controls the collection, holding, processing, or use of personal data in Mauritius, and to controllers outside Mauritius that use equipment located in the country, with exemptions for purely personal or household processing, journalism, artistic expression, and certain national-security activities. All controllers must register with the Data Protection Commissioner before processing; failure to register is a criminal offence carrying a fine of up to MUR 200,000 and imprisonment of up to five years. The Act enshrines eight data protection principles and grants data subjects rights of access, rectification, erasure, objection to direct marketing, and protection against automated decision-making with significant effects. Breach notification to the Commissioner is required without undue delay and, where feasible, within 72 hours, with direct notice to affected individuals for high-risk breaches. Cross-border transfers are permitted only to countries assessed as adequate by the Commissioner, or under specific safeguards such as standard contractual clauses or binding corporate rules. Enforcement rests with the Data Protection Commissioner, who heads an independent Data Protection Office that is not subject to the direction of any other authority and may issue enforcement notices, stop-processing orders, and conduct audits and investigations. Having modernised to a GDPR-style standard relatively early (2017 - 18), Mauritius operates one of the more sophisticated single-statute regimes in the East Africa / Indian Ocean grouping.
| Topic | Instruments | Cases | Coverage |
|---|---|---|---|
| Data Protection | 1 | 0 | ◐ |
| AI Governance | 2 | 0 | ◐ |
| Fintech | 5 | 0 | ◐ |
| Cybercrime | 1 | 0 | ◐ |
| Digital Rights | 1 | 0 | ◐ |
| Platform Liability | 0 | 0 | ○ |
| Telecoms | 1 | 0 | ◐ |
● Covered ◐ Partially covered ○ Not yet covered
Information and Communication Technologies Act 2001, Section 46 (online communications offences, as amended) (Mauritius)
The Cybersecurity and Cybercrime Act 2021 (Act No. 16 of 2021)
Enacted 24 Nov 2021
National Payment Systems (Authorisation and Licensing) Regulations 2021
Enacted 1 Jun 2021
Financial Services (Crowdfunding) Rules 2021
Enacted 4 Sept 2021
Financial Services (Peer to Peer Lending) Rules 2020
Enacted 15 Aug 2020
Virtual Asset and Initial Token Offering Services Act 2021
Enacted 17 Dec 2021
National Payment Systems Act 2018 (Act 17 of 2018)
Enacted 19 Dec 2018
National Artificial Intelligence Strategy and FAIR Guidelines (2026)
Enacted 9 Apr 2026
Mauritius Artificial Intelligence Strategy (2018)
Enacted 1 Nov 2018
Data Protection Act 2017
Enacted 23 Dec 2017
The framework rests on a single primary Act; ATLPF holds no record of subsidiary regulations or codes of practice elaborating its operation. The principal documentation gap is the absence of recorded implementing instruments rather than any obvious substantive deficiency in the law itself.