MU

Mauritius

East Africa

10Instruments
0Cases
4Regulators
65%Coverage
Overview

Mauritius has one of the more modern data protection regimes on the continent. Its primary instrument, the Data Protection Act 2017 (Act No. 20 of 2017), was published on 23 December 2017 and entered into force on 15 January 2018, repealing and replacing the Data Protection Act 2004. The 2017 Act was deliberately aligned with the EU GDPR, reflecting the country's role as a regional financial-services hub with substantial cross-border data flows. It applies to any person who controls the collection, holding, processing, or use of personal data in Mauritius, and to controllers outside Mauritius that use equipment located in the country, with exemptions for purely personal or household processing, journalism, artistic expression, and certain national-security activities. All controllers must register with the Data Protection Commissioner before processing; failure to register is a criminal offence carrying a fine of up to MUR 200,000 and imprisonment of up to five years. The Act enshrines eight data protection principles and grants data subjects rights of access, rectification, erasure, objection to direct marketing, and protection against automated decision-making with significant effects. Breach notification to the Commissioner is required without undue delay and, where feasible, within 72 hours, with direct notice to affected individuals for high-risk breaches. Cross-border transfers are permitted only to countries assessed as adequate by the Commissioner, or under specific safeguards such as standard contractual clauses or binding corporate rules. Enforcement rests with the Data Protection Commissioner, who heads an independent Data Protection Office that is not subject to the direction of any other authority and may issue enforcement notices, stop-processing orders, and conduct audits and investigations. Having modernised to a GDPR-style standard relatively early (2017 - 18), Mauritius operates one of the more sophisticated single-statute regimes in the East Africa / Indian Ocean grouping.

Topic coverage
TopicInstrumentsCasesCoverage
Data Protection10
AI Governance20
Fintech50
Cybercrime10
Digital Rights10
Platform Liability00
Telecoms10

● Covered  ◐ Partially covered  ○ Not yet covered

Instruments
mu-icta-s46-2018·Act

Information and Communication Technologies Act 2001, Section 46 (online communications offences, as amended) (Mauritius)

MauritiusDigital RightsTelecomsIn Force
Verified
mu-cyber-2021·Act

The Cybersecurity and Cybercrime Act 2021 (Act No. 16 of 2021)

MauritiusCybercrimeIn Force
Verified

Enacted 24 Nov 2021

mu-nps-authlicensing-2021·Regulation

National Payment Systems (Authorisation and Licensing) Regulations 2021

MauritiusFintechIn Force
Verified

Enacted 1 Jun 2021

mu-crowdfunding-2021·Regulation

Financial Services (Crowdfunding) Rules 2021

MauritiusFintechIn Force
Verified

Enacted 4 Sept 2021

mu-p2plending-2020·Regulation

Financial Services (Peer to Peer Lending) Rules 2020

MauritiusFintechIn Force
Verified

Enacted 15 Aug 2020

mu-vaitos-2021·Act

Virtual Asset and Initial Token Offering Services Act 2021

MauritiusFintechIn Force
Verified

Enacted 17 Dec 2021

mu-npsact-2018·Act

National Payment Systems Act 2018 (Act 17 of 2018)

MauritiusFintechIn Force
Verified

Enacted 19 Dec 2018

mu-ai-2026·Guidance

National Artificial Intelligence Strategy and FAIR Guidelines (2026)

MauritiusAI GovernanceProposed
Verified

Enacted 9 Apr 2026

mu-ai-2018·Guidance

Mauritius Artificial Intelligence Strategy (2018)

MauritiusAI GovernanceProposed
Verified

Enacted 1 Nov 2018

mu-dpa-2017·Act

Data Protection Act 2017

MauritiusData ProtectionIn Force
Verified

Enacted 23 Dec 2017

Notable gaps

The framework rests on a single primary Act; ATLPF holds no record of subsidiary regulations or codes of practice elaborating its operation. The principal documentation gap is the absence of recorded implementing instruments rather than any obvious substantive deficiency in the law itself.