The Cybersecurity and Cybercrime Act 2021 in Mauritius

Published 30 August 2026 · Lex Aquila Advocates

The Cybersecurity and Cybercrime Act 2021 creates offences and procedures concerning misuse of computer systems, electronic data and online communications in Mauritius. It is relevant to conduct such as unauthorised access, interference with data or systems, and other forms of cyber-enabled wrongdoing. A cyber incident can also create evidence, employment, contract and data-protection issues, so the legal response should be coordinated rather than improvised.

Why the 2021 Act was introduced

Digital fraud, account compromise, ransomware, malicious communications and misuse of data can cause immediate harm across borders. The 2021 Act supplies a modern statutory framework for cybercrime and related investigation. It does not mean that every unpleasant online interaction is a cybercrime, nor does a criminal complaint automatically resolve a commercial loss. The precise conduct, device, account records and communications must be preserved. A business should separate technical containment from blame while the facts are still being established.

Offences created by the Act

The Act addresses a range of conduct involving computer systems and data. The correct characterisation depends on intent, authorisation, what was accessed or changed, and the evidence available. It is unsafe to use criminal labels as negotiating language before the facts have been checked. Preserve original emails, headers, logs, URLs, screenshots and system records, including the time and source of collection. An investigator or court will need more than a cropped image with no account context.

Unauthorised access and interference

Access may be unauthorised even where the person had some prior relationship with the organisation, such as an employee, contractor or former director. Likewise, deleting, altering, blocking or disrupting data can have consequences beyond a dispute over who owns an account. Businesses should control access through named accounts, least-privilege permissions and prompt offboarding. Shared passwords make it harder to establish what happened and can expose an organisation to avoidable risk. Document changes to access rights and retain audit logs.

Investigative powers and preservation orders

Cyber investigations are vulnerable to rapid loss of evidence. The Act provides investigation-related mechanisms, but businesses and individuals should not take that as an invitation to conduct their own intrusive searches or interception. When an incident is discovered, preserve relevant systems and records lawfully, keep a chain of custody and obtain appropriate technical help. Do not alter the source device merely to create a cleaner narrative. Formal requests or orders should be read carefully and complied with through a controlled process.

Obligations on service providers

Service providers may receive lawful requests or orders relating to data and must understand their statutory and contractual responsibilities. They should have a process for verifying the request, preserving relevant material, involving legal and security personnel and documenting the response. The answer is not always to disclose everything in the system; scope, confidentiality, privilege, data-protection duties and technical feasibility can matter. A written escalation route prevents a front-line employee from making a high-risk decision alone.

Interaction with the Data Protection Act 2017

A cyber incident may involve personal data, which can bring the Data Protection Act 2017 into play alongside the criminal-law framework. The two questions are distinct: one concerns possible offences and investigation; the other concerns responsible handling of people’s information and potential notification duties. Preserve the facts needed for both. The practical privacy duties are explained in our Data Protection Act compliance guide.

Responding to a cyber incident

The first hours matter. Isolate affected systems where appropriate, preserve logs and devices, reset compromised credentials, identify a decision-maker and record every material step. Notify insurers, banks, customers, regulators or law-enforcement bodies only after understanding the legal and operational position, unless immediate reporting is required. Avoid public statements that guess at cause or scope. A short incident chronology, backed by technical evidence, enables a more reliable decision about complaint, recovery, employment action and communication.

Practical preparation before taking formal steps

Every organisation should know who can authorise emergency technical steps, who owns the relationship with its IT provider and where critical logs and backups are held. Record the first report, affected systems, accounts involved, containment actions and the people who handled evidence. Preserve a copy before wiping or rebuilding a device where it is safe to do so. A technically successful recovery can still be legally weak if the evidence trail has been lost.

For individuals, do not respond to compromise by deleting the account, threatening the suspected person or circulating accusations online. Change credentials from a safe device, preserve notices and messages, contact the relevant platform or financial institution where appropriate, and obtain help if there is immediate risk. Employers should distinguish a legitimate security investigation from a punitive search of staff devices. The scope, authority and privacy implications of each step should be recorded.

Related resources: the civil and commercial law hub, online defamation, partnership disputes, small claims and a first consultation.

A written incident plan should include a contact list that remains available if normal email or file systems fail. It should identify outside forensic support, insurers, banks and senior decision-makers, while keeping legal advice confidential where appropriate. Rehearsing the plan is valuable: it reveals whether the business can actually preserve evidence, make decisions and communicate responsibly under pressure.

After containment, conduct a documented review of root cause, affected records and corrective measures. That review should feed into security improvements and any necessary legal assessment, rather than ending once systems are back online.

That preparation is particularly important where an incident spans several systems or a third-party provider. A clear contemporaneous record lets the organisation distinguish confirmed facts from early assumptions.

Frequently asked questions

What conduct is a cybercrime in Mauritius?

The Act covers various forms of unlawful conduct involving computer systems or data, including unauthorised access and interference. Whether a particular act is criminal depends on the statutory elements and evidence, not simply on whether it was harmful or offensive.

Must a company report a cyber incident?

Reporting duties depend on the incident and may arise under more than one legal or regulatory framework, including data protection where personal data is involved. Contain and document the incident promptly, then obtain advice on the reporting position.

How does the Act affect employers?

Employers should use lawful access controls, clear policies and documented offboarding. Alleged staff misuse should be investigated carefully; an employment dispute should not be assumed to prove a cybercrime.

How Lex Aquila Advocates can help

Lex Aquila Advocates can advise on the legal issues arising from a suspected cyber incident, review the communications and records preserved, and address related civil or commercial proceedings where instructed. Visit our civil and commercial practice page. Contact the chambers on use the enquiry form; enquire on WhatsApp; or call +230 5858 7956 · urgent matters.

This article is general legal information for Mauritius, not legal advice. For advice on your situation, consult a barrister.

Your Circumstances

The next step is specific.

For advice on an individual matter, contact the chambers with a concise outline.