Skip to main content

Mauritius DPA

Data Protection Act 2017

GDPR-aligned data protection law requiring Data Protection Officer appointment and breach notification to Commissioner.

Jurisdiction

Mauritius

MU

Enacted

Nov 15, 2017

Effective

Jan 15, 2018

Enforcement

Data Protection Commissioner

GDPR-aligned framework

Who Must Comply

This law applies to:

  • Data controllers and processors in Mauritius
  • Entities processing data of Mauritian residents
  • Public bodies processing personal data

Capability triggers:

automatedDecisionMaking (increases)
Required Increases applicability

Who bears obligations:

Safety Provisions

  • Mandatory Data Protection Officer for certain controllers
  • Breach notification to Data Protection Commissioner
  • Data Protection Impact Assessment for high-risk processing
  • Right to object to automated processing
  • Cross-border transfer restrictions

Enforcement

Enforced by

Data Protection Commissioner

Penalties

MUR 2M; criminal (up to 10yr)

Max fine: $2,000,000
Criminal liability(up to 10y)

Fines up to MUR 2 million or 10 years imprisonment

Quick Facts

Binding
Yes
Mental Health Focus
Yes
Child Safety Focus
No
Algorithmic Scope
Yes

Why It Matters

Mauritius's GDPR-aligned framework creates familiar compliance pathway for European AI companies expanding to African markets.

Cite This

APA

Mauritius. (2017). Data Protection Act 2017. Retrieved from https://nope.net/regs/mu-dpa-2017

BibTeX

@misc{mu_dpa_2017,
  title = {Data Protection Act 2017},
  author = {Mauritius},
  year = {2017},
  url = {https://nope.net/regs/mu-dpa-2017}
}