Tracker / Mauritius / 2012 / Anonymised respondents (2)
§ Tracker · Mauritius · DPO · 2012

Anonymised respondents (2)

No offence found; remedial efforts proven. DPO, 14 May 2012.

Record ID
mu-dpo-2012-0007
Case reference
DPO/DEC/7
Jurisdiction
Mauritius
Regulator
DPO
Type
determination
Date decided
14 May 2012
Respondent type
private
Sector
banking
Violations
inadequate protection of card data (alleged)
Provisions cited
s.11 DPA 2004, s.22 DPA 2004, s.24 DPA 2004
Outcome
no offence found; remedial efforts proven
Status
final
Source
Official document ↗
Source integrity
SHA-256 48c50a6a5a608fa9…
Record verified
30 July 2026

The facts

The complainant alleged that a hypermarket and its payment provider were storing debit and credit card details at the point of sale, showing receipts on which his card number was recorded and warning that the details could enable fraud if servers were hacked or receipts stolen. The enquiry found the respondents remedied the risks by adopting a compliance and security programme to safeguard customers' personal data, and the complainant declared himself satisfied.

Orders and outcome

The Commissioner held it proven beyond reasonable doubt that the respondents had displayed the required remedial efforts, restated the duties of information, consent and security applying to cardholder data, and required continued compliance with international and local standards on pain of prosecution. Dated 14 May 2012.

PAYMENT-CARDS · SECURITY-MEASURES · BANKING

Cite this decision

DPO (Mauritius), Anonymised respondents (2), DPO/DEC/7, determination of 14 May 2012. African Data Protection Enforcement Tracker, Law Lab Africa Research, https://research.lawlab.africa/tracker/mauritius/dpo/2012/decision-7-card-receipts-storage/ (accessed 30 August 2026).

Same respondent


Track Mauritius enforcement

Get decision alerts by email

Tell us your jurisdictions and we email you when a regulator's decision passes verification. Privacy.