Skip to main content

Mauritius DPA

Data Protection Act 2017

GDPR-aligned data protection law requiring Data Protection Officer appointment and breach notification to Commissioner.

Jurisdiction

Mauritius

Enacted

Nov 15, 2017

Effective

Jan 15, 2018

Enforcement

Data Protection Commissioner

GDPR-aligned framework

Mauritius Data Protection Office

Why It Matters

Mauritius's GDPR-aligned framework creates familiar compliance pathway for European AI companies expanding to African markets.

At a Glance

Applies to

AI CompanionMental Health AppGeneral Chatbot

Who Must Comply

  • Data controllers and processors in Mauritius
  • Entities processing data of Mauritian residents
  • Public bodies processing personal data

Safety Provisions

  • Mandatory Data Protection Officer for certain controllers
  • Breach notification to Data Protection Commissioner
  • Data Protection Impact Assessment for high-risk processing
  • Right to object to automated processing
  • Cross-border transfer restrictions

Compliance & Enforcement

Penalties

MUR 2M; criminal (up to 10yr)

Criminal liability

View on map

Mauritius

Focus Areas

Mental health & crisis
Algorithmic accountability

Cite This

APA

Mauritius. (2017). Data Protection Act 2017.

Last updated January 22, 2026. Verify against primary sources before relying on this information.