Anonymised respondents (2)
No offence found; remedial efforts proven. DPO, 14 May 2012.
The facts
The complainant alleged that a hypermarket and its payment provider were storing debit and credit card details at the point of sale, showing receipts on which his card number was recorded and warning that the details could enable fraud if servers were hacked or receipts stolen. The enquiry found the respondents remedied the risks by adopting a compliance and security programme to safeguard customers' personal data, and the complainant declared himself satisfied.
Orders and outcome
The Commissioner held it proven beyond reasonable doubt that the respondents had displayed the required remedial efforts, restated the duties of information, consent and security applying to cardholder data, and required continued compliance with international and local standards on pain of prosecution. Dated 14 May 2012.
Cite this decision
Same respondent
- 24 June 2011 · no prejudice found (genuine error)
- 12 May 2014 · disclosure held to be processing
- 22 April 2016 · no evidence of unlawful disclosure
Track Mauritius enforcement
Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.