§ Dossier · EAST AFRICA · updated 22 July 2026
207
published decisions tracked
DPO: 207
2025-11
latest decision
data updated 22 July 2026
The law
Data Protection Act 2017 (Act 20 of 2017, amended 2023) IN FORCE
commenced 2018-01-15 · Official full text ↗
- Scope
- Controllers/processors established in Mauritius and those using equipment in Mauritius.
- Key obligations
- GDPR-aligned principles, lawful bases, DPIAs; Registration of controllers and processors with the DPO; Records of processing
- DPO required
- Data protection officer designation per Act.
- Registration
- Yes: registration/renewal with the Data Protection Office.
- Cross-border transfers
- Adequacy/safeguards/consent conditions for transfers (s.36).
- Breach notification
- 72 hours to the Commissioner where feasible; subjects notified for high risk.
- Penalties
- Fines up to MUR 200,000 and imprisonment up to 5 years for offences.
- Authority
- Data Protection Office (Commissioner for Data Protection)
Verified 2026-07-07
Enforcement record
Decision types: Determination · 207
Actions by year
Published decisions only; a year with no bar had no published decision that we could find.
Outcomes
First-listed outcome of each tracked decision.Sectors
Sector of the respondent in each tracked decision.
01Filter or search the decisions below
02Click a result to preview its summary
03Open the full record for citation and sources
Related reading
Analysis is at lawlab.africa/analysis;
method, inclusion rules and the correction policy are on the
methodology page.
Track Mauritius
Get decision alerts by email
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.