The Data Protection Act 2017 regulates how Mauritian organisations collect, use, store, disclose and otherwise process personal data. Compliance is not achieved by placing a generic privacy notice on a website: the organisation must know what data it holds, why it uses it, who receives it and how it will protect the individuals concerned. The Act is administered by the Data Protection Commissioner.
Scope of the Data Protection Act 2017
The Act applies to processing of personal data within its scope and can affect businesses of many sizes, as well as employers, associations and service providers. “Personal data” is broader than a customer’s name: it can include contact details, identification records, staff files, online identifiers and information that identifies a person in context. Start with a data map. List the systems, files, paper records, apps and outsourced providers that touch personal information, rather than concentrating only on the company website.
Roles: controller, processor and data subject
A controller determines why and how personal data is processed; a processor handles data on the controller’s behalf; the data subject is the individual to whom the data relates. These roles carry different responsibilities, and a contract label does not decide the question by itself. A controller using payroll, cloud, marketing or security suppliers should understand their roles and agree appropriate instructions, confidentiality, security and assistance arrangements. Responsibility cannot simply be outsourced with the data.
Lawful bases for processing
Before collecting or using data, identify the lawful basis that genuinely fits the purpose. Consent can be appropriate in some settings, but it should not be treated as the only available or always safest basis, especially where there is an imbalance of power. The purpose should be stated clearly and data should not later be repurposed merely because it may be commercially useful. Keep a record of the decision, what information was given to individuals and how they can exercise their rights.
Data subject rights including objection
Individuals have rights concerning their personal data, including rights of access and correction, and may have grounds to object to particular processing. A practical compliance programme gives staff a route for recognising and escalating these requests. Do not answer casually through a social-media inbox or make changes to a record without checking identity and authority. Log the request, preserve the relevant data, consider exemptions where applicable and communicate a reasoned outcome. Good records make a defensible response possible.
Security obligations and breach notification
Security must be proportionate to the data and risk. Access controls, unique accounts, secure backups, update management, staff training and a tested response plan are more useful than a policy that nobody follows. When an incident occurs, first contain it without destroying evidence; then identify what data, people, systems and recipients are affected. The Act can require notification in relevant circumstances, so a business should know who decides, who contacts the Commissioner and how affected individuals will be informed.
Transfers of data outside Mauritius
Sending data to an overseas cloud service, group company or supplier can be a transfer even when nobody thinks of it as an export. Before doing so, identify the destination, the recipient, the purpose, security arrangements and the legal mechanism that supports the transfer. The organisation should also consider onward transfers and access by support teams. “Our provider is well known” is not a complete compliance assessment. The contract, privacy information and technical controls should tell the same story.
Enforcement, penalties and practical compliance steps
The Data Protection Commissioner has oversight and enforcement functions under the Act. Rather than beginning with fear of penalties, begin with an honest inventory: data map, lawful-basis record, privacy notices, processor contracts, access controls, retention rules and incident plan. Repeat the review when the business introduces a new app, monitoring tool or marketing campaign. A cyberattack may engage other legal duties as well; see the Cybersecurity and Cybercrime Act 2021.
Practical preparation before taking formal steps
A useful compliance review follows the data rather than the organisation chart. Walk through recruitment, customer onboarding, payment, marketing, security cameras, website forms, staff communications and records disposal. For each activity, record the personal data used, purpose, lawful basis, recipients, location, retention period, security measures and person responsible. Then compare that record with the privacy notice, contracts and actual technical settings. Differences between policy and practice are where risk usually appears.
Staff need a simple escalation rule: do not delete, export, disclose or respond to a data request or incident without following the approved process. Test that rule with a mock lost-device, phishing or misdirected-email scenario. The aim is not a shelf of policies but a response that works on a difficult afternoon. Changes to software, analytics, surveillance or outsourced processing should trigger the same assessment before deployment, not after a complaint.
Related resources: the civil and commercial law hub, online defamation, partnership disputes and legal assistance at a police station.
Retention deserves the same attention as collection. Keeping data indefinitely “just in case” increases exposure and makes access requests, breaches and disposal harder to manage. Set retention periods by record type, identify legitimate holds where a dispute or investigation requires preservation, and use secure deletion procedures. That simple discipline also improves the accuracy of the data a business continues to use.
Senior management should receive concise reporting on new high-risk processing, incidents and unresolved requests. Accountability is easier to demonstrate when decisions, owners and follow-up actions are recorded rather than left to informal assurances.
Frequently asked questions
Does the Act apply to small businesses?
Size is not a safe exemption from data-protection duties. A small business that processes customers’ or employees’ personal data should assess its obligations under the Act and adopt measures proportionate to its processing and risk.
What must I do after a data breach?
Contain the incident, preserve evidence, identify the data and people affected, and assess whether notification is required. A pre-assigned incident team and a written log make a pressured response more reliable.
Can I send personal data overseas?
Transfers outside Mauritius require a considered legal and practical assessment. Check the destination, recipient, safeguards, contractual terms and what individuals have been told before transferring data.
How Lex Aquila Advocates can help
Lex Aquila Advocates can review a data-protection concern against the organisation’s notices, contracts, internal records and relevant correspondence, then advise on the civil and commercial legal issues identified. Visit our civil and commercial practice page. Contact the chambers on use the enquiry form; enquire on WhatsApp; or call +230 5858 7956 · urgent matters.
This article is general legal information for Mauritius, not legal advice. For advice on your situation, consult a barrister.