Data Protection in Mauritius: Obligations Under the Data Protection Act 2017
The principal obligations imposed by the Data Protection Act 2017 on data controllers and data processors.
The Data Protection Act 2017 establishes a comprehensive framework for the protection of personal data in Mauritius. The Act applies to data controllers established in Mauritius and to data controllers not established in Mauritius where they process personal data of data subjects who are in Mauritius. The Data Protection Commissioner, established under Section 5, oversees compliance.
Data Protection Principles
Section 8 of the Data Protection Act 2017 sets out eight data protection principles:
- Personal data shall be processed lawfully, fairly, and in a transparent manner
- Personal data shall be collected for specified, explicit, and legitimate purposes
- Personal data shall be adequate, relevant, and limited to what is necessary
- Personal data shall be accurate and, where necessary, kept up to date
- Personal data shall not be kept longer than necessary
- Personal data shall be processed securely
- The data controller shall be responsible for, and able to demonstrate compliance with, the above principles
- Personal data shall not be transferred outside Mauritius unless adequate protection is ensured
Data Subject Rights
Part IV confers the following rights: the right of access (Section 25), the right to rectification (Section 26), the right to erasure (Section 27), the right to restrict processing (Section 28), the right to data portability (Section 29), and the right to object (Section 30).
Breach Notification
Section 32 requires a data controller to notify the Data Protection Commissioner of a personal data breach within seventy-two hours. Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, those data subjects must also be notified without undue delay.
Data Protection Impact Assessments
Section 33 requires data controllers to carry out a Data Protection Impact Assessment where processing is likely to result in a high risk to the rights and freedoms of data subjects. This includes systematic and extensive profiling, processing of sensitive data on a large scale, and systematic monitoring of public areas.
Penalties
The Act provides for criminal penalties of up to MUR 5 million or imprisonment for up to five years for serious offences. Administrative penalties may be imposed by the Data Protection Commissioner under Part VIII of the Act.
This article is for general information purposes only and does not constitute legal advice.
Need Legal Advice?
Discuss Your Situation with Our Team
Our attorneys are available to provide tailored advice on your specific situation. Schedule a confidential consultation today.
Contact Us